6
CVSSv2

CVE-2015-0277

Published: 17/08/2015 Updated: 07/11/2023
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Service Provider (SP) in PicketLink prior to 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote malicious users to log in to other users' accounts via a crafted SAML assertion. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6254 for lack of validation for the Destination attribute in a Response element in a SAML assertion.

Vulnerable Product Search on Vulmon Subscribe to Product

picketlink picketlink

Vendor Advisories

A flaw was found in the way PicketLink's Service Provider and Identity Provider handled certain requests A remote attacker could use this flaw to log to a victim's account via PicketLink ...