Description
Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2284-1 | opensaml2 security update |
EUVD |
EUVD-2022-5052 | Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." |
Github GHSA |
GHSA-qwwj-qj3f-9hv7 | Improper Authentication in OpenSAML |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T22:28:40.875Z
Reserved: 2011-03-10T00:00:00.000Z
Link: CVE-2011-1411
No data.
Status : Modified
Published: 2011-09-02T23:55:04.240
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-1411
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA