Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
opensaml vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2014-3603
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) prior to 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50...
Shibboleth Identity Provider
Shibboleth Opensaml Java
4.3
CVSSv2
CVE-2015-1796
The PKIX trust engines in Shibboleth Identity Provider prior to 2.4.4 and OpenSAML Java (OpenSAML-J) prior to 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote malicious users to impersonate an entity via a certifica...
Shibboleth Identity Provider
Shibboleth Opensaml Java
5.8
CVSSv2
CVE-2011-1411
Shibboleth OpenSAML library 2.4.x prior to 2.4.3 and 2.5.x prior to 2.5.1, and IdP prior to 2.3.2, allows remote malicious users to forge messages and bypass authentication via an "XML Signature wrapping attack."
Shibboleth Opensaml 2.4.0
Shibboleth Opensaml 2.4.1
Shibboleth Opensaml 2.4.2
Shibboleth Opensaml 2.5.0
Shibboleth Shibboleth-identity-provider 2.2.0
Shibboleth Shibboleth-identity-provider 2.1.5
Shibboleth Shibboleth-identity-provider 2.1.4
Shibboleth Shibboleth-identity-provider 2.1.3
Shibboleth Shibboleth-identity-provider 2.3.0
Shibboleth Shibboleth-identity-provider 2.2.1
Shibboleth Shibboleth-identity-provider 2.1.0
Shibboleth Shibboleth-identity-provider 2.0.0
Shibboleth Shibboleth-identity-provider
Shibboleth Shibboleth-identity-provider 2.1.2
Shibboleth Shibboleth-identity-provider 2.1.1
7.5
CVSSv2
CVE-2009-3474
OpenSAML 2.x prior to 2.2.1 and XMLTooling 1.x prior to 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x prior to 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote malicious users to use a certificate for both signing and encrypti...
Internet2 Opensaml 2.1.0
Internet2 Xmltooling 1.2.0
Internet2 Opensaml 2.2.0
Internet2 Opensaml 2.0
Internet2 Xmltooling 1.0.1
Internet2 Xmltooling 1.1.0
Internet2 Xmltooling 1.1.1
Internet2 Shibboleth-sp 2.2
Internet2 Shibboleth-sp 2.1
Internet2 Shibboleth-sp 1.3.1
Internet2 Shibboleth-sp 2.0
Internet2 Shibboleth-sp 1.3f
Internet2 Shibboleth-sp 1.3b
Internet2 Shibboleth-sp 1.3.2
6.8
CVSSv2
CVE-2017-16853
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML prior to 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enfo...
Shibboleth Opensaml
Debian Debian Linux 8.0
Debian Debian Linux 9.0
9.3
CVSSv2
CVE-2009-3476
Buffer overflow in OpenSAML prior to 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x prior to 1.3.4, and XMLTooling prior to 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x prior to 2.2.1, allows remote malicious users to cause a denial o...
Internet2 Shibboleth-sp 1.3.2
Internet2 Shibboleth-sp 1.3.3
Internet2 Shibboleth-sp 1.3.1
Internet2 Shibboleth-sp 1.3f
Internet2 Opensaml 1.1
Internet2 Opensaml 1.1.1
Internet2 Xmltooling 1.1.0
Internet2 Xmltooling 1.0.1
Internet2 Xmltooling 1.1.1
Internet2 Xmltooling 1.2.0
Internet2 Xmltooling 1.2.1
Internet2 Shibboleth-sp 2.0
Internet2 Shibboleth-sp 2.1
Internet2 Shibboleth-sp 2.2
NA
CVE-2023-36661
Shibboleth XMLTooling prior to 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
Shibboleth Xmltooling
Debian Debian Linux 11.0
Debian Debian Linux 12.0
5
CVSSv2
CVE-2015-0851
XMLTooling-C prior to 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote malicious users to cause a denial of service (crash) via schema-invalid XML data.
Xmltooling Project Xmltooling
5
CVSSv2
CVE-2019-9628
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propaga...
Xmltooling Project Xmltooling
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 18.10
Opensuse Leap 15.0
Opensuse Leap 42.3
7.5
CVSSv2
CVE-2017-11430
OmniAuth OmnitAuth-SAML 1.9.0 and previous versions may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to p...
Omnitauth-saml Project Omnitauth-saml
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
administrator privileges
CVE-2024-1579
hardcoded
CVE-2023-20198
CVE-2024-33587
CVE-2024-33449
CVE-2024-4308
HTML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »