Description
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-6274-1 | XMLTooling vulnerability |
References
History
Mon, 05 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-05T15:56:49.910Z
Reserved: 2023-06-25T00:00:00.000Z
Link: CVE-2023-36661
Updated: 2024-08-02T16:52:54.047Z
Status : Modified
Published: 2023-06-25T22:15:21.403
Modified: 2025-05-05T16:15:42.010
Link: CVE-2023-36661
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN