İçeriğe atla
Noroxi

Shibboleth kayıtları

shibboleth üreticisine ait 18 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %5,6
Pre-auth RCE
0
Düzeltme kaydı olan
%77,8
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

18 kayıt
  • CVE-2022-24129
    34İzleyin

    The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction o

    YüksekCVSS 8,2Kavram kanıtıEPSS %6

    shibboleth · oidc op4 Şub 2022

  • CVE-2017-16853
    32İzleyin

    The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to pr

    YüksekCVSS 8,1İstismar yokEPSS %1

    shibboleth · opensaml16 Kas 2017

  • CVE-2017-16852
    32İzleyin

    shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to prop

    YüksekCVSS 8,1İstismar yokEPSS %1

    shibboleth · service provider16 Kas 2017

  • CVE-2023-36661
    31İzleyin

    Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element.

    YüksekCVSS 7,5SilahlaştırılmışEPSS %3

    shibboleth · xmltooling25 Haz 2023

  • CVE-2021-31826
    31İzleyin

    Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature.

    YüksekCVSS 7,5İstismar yokEPSS %2

    shibboleth · service provider27 Nis 2021

  • CVE-2020-27978
    31İzleyin

    Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw.

    YüksekCVSS 7,5İstismar yokEPSS %2

    shibboleth · identity provider28 Eki 2020

  • CVE-2019-19191
    31İzleyin

    Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service use

    YüksekCVSS 7,8İstismar yokEPSS %0

    shibboleth · service provider21 Kas 2019

  • CVE-2010-2450
    30İzleyin

    The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which i

    YüksekCVSS 7,5İstismar yokEPSS %1

    shibboleth · service provider7 Kas 2019

  • CVE-2023-22947
    29İzleyin

    Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local at

    YüksekCVSS 7,3İstismar yokEPSS %0

    shibboleth · service provider10 Oca 2023

  • CVE-2018-0489
    27İzleyin

    Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digita

    OrtaCVSS 6,5İstismar yokEPSS %2

    shibboleth · xmltooling-c27 Şub 2018

  • CVE-2018-0486
    26İzleyin

    Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital

    OrtaCVSS 6,5İstismar yokEPSS %2

    shibboleth · xmltooling-c13 Oca 2018

  • CVE-2011-1411
    24İzleyin

    Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and b

    OrtaCVSS 5,8İstismar yokEPSS %2

    shibboleth · opensaml2 Eyl 2011

  • CVE-2014-3603
    23İzleyin

    The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6

    OrtaCVSS 5,9İstismar yokEPSS %1

    shibboleth · identity provider4 Nis 2019

  • CVE-2011-2516
    22İzleyin

    Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other pr

    OrtaCVSS 5,0İstismar yokEPSS %8

    apache · xml security for c\+\+11 Tem 2011

  • CVE-2013-6440
    21İzleyin

    The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set t

    OrtaCVSS 5,0İstismar yokEPSS %3

    shibboleth · opensaml14 Şub 2014

  • CVE-2021-28963
    21İzleyin

    Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.

    OrtaCVSS 5,3İstismar yokEPSS %1

    shibboleth · service provider22 Mar 2021

  • CVE-2015-2684
    17İzleyin

    Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML mess

    OrtaCVSS 4,0İstismar yokEPSS %2

    shibboleth · service provider31 Mar 2015

  • CVE-2015-1796
    17İzleyin

    The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 creden

    OrtaCVSS 4,3İstismar yokEPSS %1

    shibboleth · identity provider8 Tem 2015