QID 375533
Date Published: 2021-05-17
QID 375533: Shibboleth Service Provider Security Advisory (17 March 2021)
Shibboleth is a single sign-on log-in system for computer networks and the Internet.
An updated version of the Service Provider software is available which fixes a phishing vulnerability.
Affected Versions:
prior to release (V3.2.1)
QID Detection Logic(authenticated):
This QID checks to see if the target is running a vulnerable version of Shibboleth Service Provider.
Successful exploitation of the vulnerabilities allowing email addresses, logos and style sheets, or support URLs to be manipulated by an attacker.
Solution
Customers are advised to refer to Shibboleth Service Provider Security Advisory for information pertaining to remediating this vulnerability.
Vendor References
- SECADV_20210317 -
shibboleth.net/community/advisories/secadv_20210317.txt
CVEs related to QID 375533
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| secadv_20210317 |
|