Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-shibboleth-sp | May 15, 2025 | Nov 21, 2019 | |
| Suse | — | suse-upgrade-libshibsp-lite6suse-upgrade-libshibsp-lite7suse-upgrade-libshibsp-lite8suse-upgrade-libshibsp6suse-upgrade-libshibsp7suse-upgrade-libshibsp9suse-upgrade-shibboleth-spsuse-upgrade-shibboleth-sp-devel | Jan 14, 2020 | Nov 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub