Shibboleth Service Provider (SP) 3.x prior to 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
shibboleth service provider |