CVE-2025-9943
- EPSS 0.09%
- Veröffentlicht 10.09.2025 06:45:50
- Zuletzt bearbeitet 11.09.2025 17:14:10
An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attacker can explo...
CVE-2023-22947
- EPSS 0.02%
- Veröffentlicht 11.01.2023 02:15:11
- Zuletzt bearbeitet 07.04.2025 19:15:51
Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs becau...
CVE-2021-31826
- EPSS 1.48%
- Veröffentlicht 27.04.2021 04:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:18
Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.
CVE-2021-28963
- EPSS 0.49%
- Veröffentlicht 22.03.2021 08:15:13
- Zuletzt bearbeitet 21.11.2024 06:00:27
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
CVE-2019-19191
- EPSS 0.17%
- Veröffentlicht 21.11.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:17
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to fil...
CVE-2010-2450
- EPSS 0.16%
- Veröffentlicht 07.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:16:41
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself,...
CVE-2017-16852
- EPSS 0.32%
- Veröffentlicht 16.11.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as si...
- EPSS 0.46%
- Veröffentlicht 31.03.2015 14:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.