Description
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-6274-1 | XMLTooling vulnerability |
References
History
Mon, 05 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-05T15:56:49.910Z
Reserved: 2023-06-25T00:00:00.000Z
Link: CVE-2023-36661
Updated: 2024-08-02T16:52:54.047Z
Status : Modified
Published: 2023-06-25T22:15:21.403
Modified: 2026-06-17T06:06:46.773
Link: CVE-2023-36661
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-918
Server-Side Request Forgery (SSRF)
Ubuntu USN