Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2023-22947 Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to… Service Provider 3.4.1+ Fix from $1,9502023-01-11 HIGH 8.2 CVE-2022-24129EPSS 6% The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the req… Oidc Op 3.0.4+ Fix from $1,9502022-02-04 HIGH 7.5 CVE-2021-31826 Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploita… Service Provider 3.2.2+ Fix from $1,9502021-04-27 HIGH 7.5 CVE-2020-27978 Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java … Identity Provider 3.4.6+ Fix from $1,9502020-10-28 HIGH 7.8 CVE-2019-19191 Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the sh… Service Provider 3.1.0+ Fix from $1,9502019-11-21 MEDIUM 5.9 CVE-2014-3603 The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not… Identity Provider 2.4.1 / 2.6.2+ Fix from $1,6002019-04-04 MEDIUM 5.8 CVE-2011-1411 Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass aut… Opensaml after 2.3.1 Fix from $1,6002011-09-02