Shibboleth

Service Provider

8 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 10.09.2025 06:45:50
  • Last modified 11.09.2025 17:14:10

An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attacker can explo...

Exploit
  • EPSS 0.02%
  • Published 11.01.2023 02:15:11
  • Last modified 07.04.2025 19:15:51

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs becau...

Exploit
  • EPSS 1.48%
  • Published 27.04.2021 04:15:08
  • Last modified 21.11.2024 06:06:18

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

  • EPSS 0.49%
  • Published 22.03.2021 08:15:13
  • Last modified 21.11.2024 06:00:27

Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.

Exploit
  • EPSS 0.17%
  • Published 21.11.2019 18:15:12
  • Last modified 21.11.2024 04:34:17

Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to fil...

  • EPSS 0.16%
  • Published 07.11.2019 21:15:10
  • Last modified 21.11.2024 01:16:41

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself,...

  • EPSS 0.32%
  • Published 16.11.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as si...

  • EPSS 0.46%
  • Published 31.03.2015 14:59:09
  • Last modified 12.04.2025 10:46:40

Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.