The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade opensaml | Mar 31, 2025 | Mar 28, 2025 |
| Red Hat Jboss Eap | — | — | Apr 1, 2025 | Mar 28, 2025 |
| Suse | — | Upgrade opensaml-binUpgrade libsaml11Upgrade libsaml-develUpgrade libsaml8Upgrade libsaml13Upgrade opensaml-schemas | Dec 5, 2025 | Jun 5, 2025 |
| Ubuntu | — | Upgrade opensamlUpgrade opensaml2 (Ubuntu Pro) | May 22, 2025 | Mar 28, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub