Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade opensaml2 | Dec 10, 2025 | Jul 25, 2011 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 14331523 for version 12.1.1.0.0.Apply the Patch Set Update (PSU) 14331529 for version 10.3.5.0.0.Apply the Patch Set Update (PSU) 14331527 for version 10.3.6.0.0. | Apr 3, 2018 | Sep 2, 2011 |
| Ubuntu | — | Upgrade opensaml2 | Nov 19, 2024 | Sep 2, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub