2.6
CVSSv2

CVE-2009-3300

Published: 06/11/2009 Updated: 17/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x prior to 1.3.4 and 2.x prior to 2.1.5, and the Service Provider 1.3.x prior to 1.3.5 and 2.x prior to 2.3, in Internet2 Middleware Initiative Shibboleth allow remote malicious users to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms.

Vulnerable Product Search on Vulmon Subscribe to Product

internet2 identity provider 2.1.2

internet2 identity provider 2.1.3

internet2 service provider 2.2

internet2 service provider 2.1

internet2 identity provider 1.3.1

internet2 identity provider 1.3

internet2 service provider 1.3.1

internet2 service provider 1.3.2

internet2 identity provider 1.3.3

internet2 identity provider 1.3.2

internet2 identity provider 2.1.4

internet2 service provider 1.3

internet2 identity provider 2.1.0

internet2 identity provider 2.1.1

internet2 service provider 1.3.3

internet2 service provider 2.0

Vendor Advisories

Debian Bug report logs - #555608 CVE-2009-3300 Package: shibboleth-sp2; Maintainer for shibboleth-sp2 is Debian Shib Team <pkg-shibboleth-devel@listsaliothdebianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Tue, 10 Nov 2009 12:48:01 UTC Severity: serious Tags: security Fixed in versions shibbol ...
Matt Elder discovered that Shibboleth, a federated web single sign-on system is vulnerable to script injection through redirection URLs More details can be found in the Shibboleth advisory at shibbolethinternet2edu/secadv/secadv_20091104txt For the old stable distribution (etch), this problem has been fixed in version 13fdfsg1-2+etch2 ...