VYPR
Vendor

Shibboleth Project

Products
1
CVEs
8
Across products
8
Status
Private

Products

1

Recent CVEs

8
  • CVE-2022-24129HigFeb 4, 2022
    risk 0.54cvss 8.2epss 0.06

    The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

  • CVE-2019-19191HigNov 21, 2019
    risk 0.51cvss 7.8epss 0.00

    Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.

  • CVE-2021-31826HigApr 27, 2021
    risk 0.49cvss 7.5epss 0.02

    Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

  • CVE-2020-27978HigOct 28, 2020
    risk 0.49cvss 7.5epss 0.02

    Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session.

  • CVE-2010-2450HigNov 7, 2019
    risk 0.49cvss 7.5epss 0.01

    The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key…

  • CVE-2017-14313MedSep 12, 2017
    risk 0.40cvss 6.1epss 0.01

    The shibboleth_login_form function in shibboleth.php in the Shibboleth plugin before 1.8 for WordPress is prone to an XSS vulnerability due to improper use of add_query_arg().

  • CVE-2021-28963MedMar 22, 2021
    risk 0.35cvss 5.3epss 0.01

    Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.

  • CVE-2011-2516Jul 11, 2011
    risk 0.01cvss epss 0.08

    Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer…