Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
2023-06-25T22:15:21.403
2025-05-05T16:15:42.010
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | shibboleth | xmltooling | < 3.2.4 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Operating System | debian | debian_linux | 12.0 | Yes |