CVE-2023-36661
Summary
| CVE | CVE-2023-36661 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-25 22:15:00 UTC |
| Updated | 2023-07-06 18:02:00 UTC |
| Description | Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.) |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| shibboleth.net/community/advisories/secadv_20230612.txt |
MISC |
shibboleth.net |
|
| Debian -- Security Information -- DSA-5432-1 xmltooling |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199637 Ubuntu Security Notification for XMLTooling Vulnerability (USN-6274-1)
- 379443 Shibboleth Service Provider Security Advisory (12 June 2023)
- 6000026 Debian Security Update for xmltooling (DLA 3464-1)
- 754214 SUSE Enterprise Linux Security Update for xmltooling (SUSE-SU-2023:2975-1)
- 754234 SUSE Enterprise Linux Security Update for xmltooling (SUSE-SU-2023:3089-1)