MidnightBSD

Advisories for shibboleth

CVE-2011-1411 MEDIUM

Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
shibboleth shibboleth-identity-provider 2.0.0
shibboleth shibboleth-identity-provider *
shibboleth opensaml 2.4.0
shibboleth shibboleth-identity-provider 2.1.2
shibboleth shibboleth-identity-provider 2.1.3
shibboleth opensaml 2.5.0
shibboleth opensaml 2.4.1
shibboleth shibboleth-identity-provider 2.3.0
shibboleth shibboleth-identity-provider 2.1.1
shibboleth shibboleth-identity-provider 2.2.0
shibboleth opensaml 2.4.2
shibboleth shibboleth-identity-provider 2.1.4
shibboleth shibboleth-identity-provider 2.1.5
shibboleth shibboleth-identity-provider 2.1.0
shibboleth shibboleth-identity-provider 2.2.1
CVE-2011-2516 MEDIUM

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-189,

Products Affected

Vendor Product Version
shibboleth shibboleth-sp 1.3.3
shibboleth shibboleth-sp 2.0
shibboleth shibboleth-sp 2.3
shibboleth shibboleth-sp 2.4
shibboleth shibboleth-sp 1.3.1
shibboleth shibboleth-sp 1.3.5
shibboleth shibboleth-sp 2.4.1
shibboleth shibboleth-sp *
shibboleth shibboleth-sp 1.3.2
shibboleth shibboleth-sp 2.2
shibboleth shibboleth-sp 2.1
shibboleth shibboleth-sp 2.3.1
shibboleth shibboleth-sp 1.3f
shibboleth shibboleth-sp 1.3.4
shibboleth shibboleth-sp 2.2.1
apache xml_security_for_c++ 1.6.0
CVE-2013-6440 MEDIUM

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
shibboleth opensaml *
shibboleth opensaml 2.4.0
shibboleth opensaml 2.5.3
shibboleth opensaml 2.5.0
internet2 opensaml 2.0
shibboleth opensaml 2.4.1
shibboleth opensaml 2.4.3
shibboleth opensaml 2.5.1
internet2 opensaml 2.2.0
shibboleth opensaml 2.4.2
internet2 opensaml 2.1.0
shibboleth opensaml 2.5.2
CVE-2015-1796 MEDIUM

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-254,

Products Affected

Vendor Product Version
shibboleth identity_provider *
shibboleth opensaml_java *
CVE-2015-2684 MEDIUM

Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
shibboleth service_provider *
debian debian_linux 7.0
CVE-2017-16852 MEDIUM

shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-347,

Products Affected

Vendor Product Version
shibboleth service_provider *
debian debian_linux 8.0
debian debian_linux 9.0
CVE-2017-16853 MEDIUM

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-347,

Products Affected

Vendor Product Version
shibboleth opensaml *
debian debian_linux 8.0
debian debian_linux 9.0
CVE-2018-0486 MEDIUM

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-347,

Products Affected

Vendor Product Version
debian debian_linux 8.0
debian debian_linux 9.0
shibboleth xmltooling-c *
debian debian_linux 7.0
CVE-2018-0489 MEDIUM

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-347,

Products Affected

Vendor Product Version
arubanetworks clearpass *
debian debian_linux 8.0
debian debian_linux 9.0
shibboleth xmltooling-c *
debian debian_linux 7.0