NA

CVE-2023-36661

Published: 25/06/2023 Updated: 06/07/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Shibboleth XMLTooling prior to 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shibboleth xmltooling

debian debian linux 11.0

debian debian linux 12.0

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Shibboleth XMLTooling before 324, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element (This is fixed in, for example, Shibboleth Service Provider 3413 on Windows) ...

Exploits

This Metasploit module chains a server side request forgery (SSRF) vulnerability (CVE-2024-21893) and a command injection vulnerability (CVE-2024-21887) to exploit vulnerable instances of either Ivanti Connect Secure or Ivanti Policy Secure, to achieve unauthenticated remote code execution All currently supported versions 9x and 22x are vulnerab ...