Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| shibboleth | shibboleth-identity-provider | 2.0.0 |
| shibboleth | shibboleth-identity-provider | * |
| shibboleth | opensaml | 2.4.0 |
| shibboleth | shibboleth-identity-provider | 2.1.2 |
| shibboleth | shibboleth-identity-provider | 2.1.3 |
| shibboleth | opensaml | 2.5.0 |
| shibboleth | opensaml | 2.4.1 |
| shibboleth | shibboleth-identity-provider | 2.3.0 |
| shibboleth | shibboleth-identity-provider | 2.1.1 |
| shibboleth | shibboleth-identity-provider | 2.2.0 |
| shibboleth | opensaml | 2.4.2 |
| shibboleth | shibboleth-identity-provider | 2.1.4 |
| shibboleth | shibboleth-identity-provider | 2.1.5 |
| shibboleth | shibboleth-identity-provider | 2.1.0 |
| shibboleth | shibboleth-identity-provider | 2.2.1 |
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-189,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| shibboleth | shibboleth-sp | 1.3.3 |
| shibboleth | shibboleth-sp | 2.0 |
| shibboleth | shibboleth-sp | 2.3 |
| shibboleth | shibboleth-sp | 2.4 |
| shibboleth | shibboleth-sp | 1.3.1 |
| shibboleth | shibboleth-sp | 1.3.5 |
| shibboleth | shibboleth-sp | 2.4.1 |
| shibboleth | shibboleth-sp | * |
| shibboleth | shibboleth-sp | 1.3.2 |
| shibboleth | shibboleth-sp | 2.2 |
| shibboleth | shibboleth-sp | 2.1 |
| shibboleth | shibboleth-sp | 2.3.1 |
| shibboleth | shibboleth-sp | 1.3f |
| shibboleth | shibboleth-sp | 1.3.4 |
| shibboleth | shibboleth-sp | 2.2.1 |
| apache | xml_security_for_c++ | 1.6.0 |
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| shibboleth | opensaml | * |
| shibboleth | opensaml | 2.4.0 |
| shibboleth | opensaml | 2.5.3 |
| shibboleth | opensaml | 2.5.0 |
| internet2 | opensaml | 2.0 |
| shibboleth | opensaml | 2.4.1 |
| shibboleth | opensaml | 2.4.3 |
| shibboleth | opensaml | 2.5.1 |
| internet2 | opensaml | 2.2.0 |
| shibboleth | opensaml | 2.4.2 |
| internet2 | opensaml | 2.1.0 |
| shibboleth | opensaml | 2.5.2 |
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| shibboleth | identity_provider | * |
| shibboleth | opensaml_java | * |
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| shibboleth | service_provider | * |
| debian | debian_linux | 7.0 |
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-347,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| shibboleth | service_provider | * |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-347,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| shibboleth | opensaml | * |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-347,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| shibboleth | xmltooling-c | * |
| debian | debian_linux | 7.0 |
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-347,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| arubanetworks | clearpass | * |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| shibboleth | xmltooling-c | * |
| debian | debian_linux | 7.0 |