CVE-2017-16853

Related Vulnerabilities: CVE-2017-16853  

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.

The MITRE CVE dictionary describes this issue as:

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.

Find out more about CVE-2017-16853 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact None

Affected Packages State

Platform Package State
Red Hat JBoss Portal Platform 6 opensaml Not affected
Red Hat JBoss Operations Network 3 opensaml Not affected
Red Hat JBoss Fuse Service Works 6 opensaml Not affected
Red Hat JBoss EAP 7 opensaml-core Not affected
Red Hat JBoss EAP 6 opensaml Not affected
Red Hat JBoss Data Virtualization 6 opensaml Not affected
Red Hat JBoss Data Grid 6 opensaml Not affected