QID 375662
Date Published: 2021-07-26
QID 375662: Shibboleth Service Provider Security Advisory (22 June 2021)
Shibboleth is a single sign-on log-in system for computer networks and the Internet.
An updated version of the Service Provider software is available which fixes a phishing vulnerability.
Affected Versions:
V3.0.0 to V3.2.2
QID Detection Logic(authenticated):
This QID checks to see if the target is running a vulnerable version of Shibboleth Service Provider.
Successful exploitation of the vulnerabilities allowing email addresses, logos and style sheets, or support URLs to be manipulated by an attacker.
Customers are advised to refer to Shibboleth Service Provider Security Advisory for information pertaining to remediating this vulnerability.
Workaround:
In cases where this is not immediately possible, adding useHeaders="true" to the ISAPI element in shibboleth2.xml will enable the usual header detection code that attempts to prevent
header smuggling. In most cases, this should not impact applications that are accessing data via server variables.
- SECADV_20210622 -
shibboleth.net/community/advisories/secadv_20210622.txt
CVEs related to QID 375662
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| secadv_20210622 |
|