The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opensaml | Mar 31, 2025 | Mar 28, 2025 |
| Red Hat Jboss Eap | — | — | Apr 1, 2025 | Mar 28, 2025 |
| Suse | — | Upgrade opensaml-binUpgrade libsaml11Upgrade libsaml8Upgrade libsaml-develUpgrade opensaml-schemasUpgrade libsaml13 | Dec 5, 2025 | Jun 5, 2025 |
| Ubuntu | — | Upgrade opensaml2 (Ubuntu Pro)Upgrade opensaml | May 22, 2025 | Mar 28, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub