Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade shibboleth-sp | Mar 23, 2021 | Mar 23, 2021 |
| Ubuntu | — | Upgrade libshibsp8Upgrade libapache2-mod-shibUpgrade shibboleth-sp-utilsUpgrade shibboleth-sp-commonUpgrade libshibsp-plugins | Apr 23, 2021 | Mar 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub