Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
shibboleth vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2012-4494
The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibly have other impacts by logging in.
Niif Shibb Auth 7.x-4.0
NA
CVE-2015-0218
Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle up to and including 2.5.9, 2.6.x prior to 2.6.7, 2.7.x prior to 2.7.4, and 2.8.x prior to 2.8.2 allows remote malicious users to hijack the authentication of arbitrary users for requests that ...
Moodle Moodle
Moodle Moodle 2.6.2
Moodle Moodle 2.6.1
Moodle Moodle 2.6.0
Moodle Moodle 2.7.3
Moodle Moodle 2.5.4
Moodle Moodle 2.5.3
Moodle Moodle 2.5.2
Moodle Moodle 2.5.1
Moodle Moodle 2.5.8
Moodle Moodle 2.5.6
Moodle Moodle 2.6.6
Moodle Moodle 2.6.4
Moodle Moodle 2.7.1
Moodle Moodle 2.8.0
Moodle Moodle 2.5.7
Moodle Moodle 2.5.5
Moodle Moodle 2.5.0
Moodle Moodle 2.6.5
Moodle Moodle 2.6.3
Moodle Moodle 2.7.2
Moodle Moodle 2.7.0
NA
CVE-2009-4527
The Shibboleth authentication module 5.x prior to 5.x-3.4 and 6.x prior to 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate malicious users to gain privileges by using an...
Niif Shib Auth 5.x-3.3
Niif Shib Auth 5.x-2.1
Niif Shib Auth 5.x-1.x
Niif Shib Auth 6.x-2.0
Niif Shib Auth 6.x-1.x
Niif Shib Auth 5.x-3.x
Niif Shib Auth 6.x-3.0
Niif Shib Auth 6.x-3.x
Niif Shib Auth 6.x-3.1
Niif Shib Auth 5.x-2.x
Niif Shib Auth 6.x-2.x
Niif Shib Auth 5.x-2.5
Niif Shib Auth 5.x-2.4
Niif Shib Auth 5.x-2.2
Niif Shib Auth 6.x-2.2
Niif Shib Auth 6.x-2.1
7.5
CVSSv3
CVE-2019-9628
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propaga...
Xmltooling Project Xmltooling
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 18.10
Opensuse Leap 15.0
Opensuse Leap 42.3
9.8
CVSSv3
CVE-2017-11427
OneLogin PythonSAML 2.3.0 and previous versions may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to poten...
Onelogin Pythonsaml
13 Github repositories
9.8
CVSSv3
CVE-2017-11428
OneLogin Ruby-SAML 1.6.0 and previous versions may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potent...
Onelogin Ruby-saml
2 Github repositories
9.8
CVSSv3
CVE-2017-11429
Clever saml2-js 2.0 and previous versions may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially...
Clever Saml2-js
9.8
CVSSv3
CVE-2017-11430
OmniAuth OmnitAuth-SAML 1.9.0 and previous versions may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to p...
Omnitauth-saml Project Omnitauth-saml
7.5
CVSSv3
CVE-2018-5387
Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication t...
Wizkunde Samlbase
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4