Shibboleth OpenSAML 2.6.0

CPE Details

Shibboleth OpenSAML 2.6.0
2.6.0
2021-08-25
13h18 +00:00
2021-08-25
13h31 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:shibboleth:opensaml:2.6.0:*:*:*:*:*:*:*

Informations

Vendor

shibboleth

Product

opensaml

Version

2.6.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2017-16853 2017-11-16 16h00 +00:00 The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.
8.1
High
CVE-2013-6440 2014-02-14 14h00 +00:00 The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.
5