QID 379443
Date Published: 2024-03-27
QID 379443: Shibboleth Service Provider Security Advisory (12 June 2023)
Shibboleth is a single sign-on log-in system for computer networks and the Internet.
CVE-2023-36661: Shibboleth XMLTooling library used in Shibboleth Service Provider software allows SSRF via a crafted KeyInfo element.
Affected Versions:
Shibboleth Service Provider version prior to 3.4.1.3
QID Detection Logic(authenticated):
This QID checks to see if the target is running a vulnerable version of Shibboleth Service Provider.
Successful exploitation of the vulnerabilities allows the attacker to perform SSRF via a crafted KeyInfo element.
Solution
Customers are advised to refer to Shibboleth Service Provider Security Advisory for information pertaining to remediating this vulnerability.
Vendor References
- SECADV_20230612 -
shibboleth.net/community/advisories/secadv_20230612.txt
CVEs related to QID 379443
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| secadv_20230612 |
|