Shibboleth kayıtları
shibboleth üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %5,6
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %77,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-347 Improper Verification of Cryptographic Signature4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-254 7PK - Security Features1
- CWE-287 Improper Authentication1
- CWE-297 Improper Validation of Certificate with Host Mismatch1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2022-24129Kavram kanıtı | The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction oshibboleth · oidc op · CWE-918 | Yüksek8,2 | — | %6,1 | 4 Şub 2022 |
32İzleyin | CVE-2017-16853İstismar yok | The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to prshibboleth · opensaml · CWE-347 | Yüksek8,1 | — | %1,4 | 16 Kas 2017 |
32İzleyin | CVE-2017-16852İstismar yok | shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to propshibboleth · service provider · CWE-347 | Yüksek8,1 | — | %1,1 | 16 Kas 2017 |
31İzleyin | CVE-2023-36661Silahlaştırılmış | Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element.shibboleth · xmltooling · CWE-918 | Yüksek7,5 | — | %2,9 | 25 Haz 2023 |
31İzleyin | CVE-2021-31826İstismar yok | Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature.shibboleth · service provider · CWE-476 | Yüksek7,5 | — | %2,0 | 27 Nis 2021 |
31İzleyin | CVE-2020-27978İstismar yok | Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw.shibboleth · identity provider · CWE-770 | Yüksek7,5 | — | %1,9 | 28 Eki 2020 |
31İzleyin | CVE-2019-19191İstismar yok | Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service useshibboleth · service provider · CWE-59 | Yüksek7,8 | — | %0,5 | 21 Kas 2019 |
30İzleyin | CVE-2010-2450İstismar yok | The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which ishibboleth · service provider · CWE-200 | Yüksek7,5 | — | %1,2 | 7 Kas 2019 |
29İzleyin | CVE-2023-22947İstismar yok | Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local atshibboleth · service provider · CWE-427 | Yüksek7,3 | — | %0,3 | 10 Oca 2023 |
27İzleyin | CVE-2018-0489İstismar yok | Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digitashibboleth · xmltooling-c · CWE-347 | Orta6,5 | — | %2,1 | 27 Şub 2018 |
26İzleyin | CVE-2018-0486İstismar yok | Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital shibboleth · xmltooling-c · CWE-347 | Orta6,5 | — | %1,5 | 13 Oca 2018 |
24İzleyin | CVE-2011-1411İstismar yok | Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bshibboleth · opensaml · CWE-287 | Orta5,8 | — | %2,3 | 2 Eyl 2011 |
23İzleyin | CVE-2014-3603İstismar yok | The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6shibboleth · identity provider · CWE-297 | Orta5,9 | — | %0,8 | 4 Nis 2019 |
22İzleyin | CVE-2011-2516İstismar yok | Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other prapache · xml security for c\+\+ · CWE-189 | Orta5,0 | — | %7,7 | 11 Tem 2011 |
21İzleyin | CVE-2013-6440İstismar yok | The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set tshibboleth · opensaml · CWE-200 | Orta5,0 | — | %2,8 | 14 Şub 2014 |
21İzleyin | CVE-2021-28963İstismar yok | Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.shibboleth · service provider · CWE-74 | Orta5,3 | — | %1,3 | 22 Mar 2021 |
17İzleyin | CVE-2015-2684İstismar yok | Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML messshibboleth · service provider · CWE-20 | Orta4,0 | — | %1,9 | 31 Mar 2015 |
17İzleyin | CVE-2015-1796İstismar yok | The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credenshibboleth · identity provider · CWE-254 | Orta4,3 | — | %1,3 | 8 Tem 2015 |
- CVE-2022-2412934İzleyin
The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction o
YüksekCVSS 8,2Kavram kanıtıEPSS %6shibboleth · oidc op4 Şub 2022
- CVE-2017-1685332İzleyin
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to pr
YüksekCVSS 8,1İstismar yokEPSS %1shibboleth · opensaml16 Kas 2017
- CVE-2017-1685232İzleyin
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to prop
YüksekCVSS 8,1İstismar yokEPSS %1shibboleth · service provider16 Kas 2017
- CVE-2023-3666131İzleyin
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element.
YüksekCVSS 7,5SilahlaştırılmışEPSS %3shibboleth · xmltooling25 Haz 2023
- CVE-2021-3182631İzleyin
Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature.
YüksekCVSS 7,5İstismar yokEPSS %2shibboleth · service provider27 Nis 2021
- CVE-2020-2797831İzleyin
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw.
YüksekCVSS 7,5İstismar yokEPSS %2shibboleth · identity provider28 Eki 2020
- CVE-2019-1919131İzleyin
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service use
YüksekCVSS 7,8İstismar yokEPSS %0shibboleth · service provider21 Kas 2019
- CVE-2010-245030İzleyin
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which i
YüksekCVSS 7,5İstismar yokEPSS %1shibboleth · service provider7 Kas 2019
- CVE-2023-2294729İzleyin
Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local at
YüksekCVSS 7,3İstismar yokEPSS %0shibboleth · service provider10 Oca 2023
- CVE-2018-048927İzleyin
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digita
OrtaCVSS 6,5İstismar yokEPSS %2shibboleth · xmltooling-c27 Şub 2018
- CVE-2018-048626İzleyin
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital
OrtaCVSS 6,5İstismar yokEPSS %2shibboleth · xmltooling-c13 Oca 2018
- CVE-2011-141124İzleyin
Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and b
OrtaCVSS 5,8İstismar yokEPSS %2shibboleth · opensaml2 Eyl 2011
- CVE-2014-360323İzleyin
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6
OrtaCVSS 5,9İstismar yokEPSS %1shibboleth · identity provider4 Nis 2019
- CVE-2011-251622İzleyin
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other pr
OrtaCVSS 5,0İstismar yokEPSS %8apache · xml security for c\+\+11 Tem 2011
- CVE-2013-644021İzleyin
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set t
OrtaCVSS 5,0İstismar yokEPSS %3shibboleth · opensaml14 Şub 2014
- CVE-2021-2896321İzleyin
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
OrtaCVSS 5,3İstismar yokEPSS %1shibboleth · service provider22 Mar 2021
- CVE-2015-268417İzleyin
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML mess
OrtaCVSS 4,0İstismar yokEPSS %2shibboleth · service provider31 Mar 2015
- CVE-2015-179617İzleyin
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 creden
OrtaCVSS 4,3İstismar yokEPSS %1shibboleth · identity provider8 Tem 2015