Description
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-20470 | Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:25:44.145Z
Reserved: 2020-10-28T00:00:00.000Z
Link: CVE-2020-27978
No data.
Status : Modified
Published: 2020-10-28T15:15:13.817
Modified: 2024-11-21T05:22:08.417
Link: CVE-2020-27978
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD