Known Vulnerabilities for products from Shibboleth
Listed below are 18 of the newest known vulnerabilities associated with the vendor "Shibboleth".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-12281 json | Not Provided | 2026-07-15 | 2026-07-15 | |
| CVE-2023-36661 json | Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo el... | 7.5 - HIGH | 2023-06-25 | 2023-07-06 |
| CVE-2023-22947 json | ** DISPUTED ** Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 ... | 7.3 - HIGH | 2023-01-11 | 2023-11-07 |
| CVE-2022-24129 json | The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficien... | 8.2 - HIGH | 2022-02-04 | 2022-02-09 |
| CVE-2021-31826 json | Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery featu... | 7.5 - HIGH | 2021-04-27 | 2023-11-07 |
| CVE-2021-28963 json | Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parame... | 5.3 - MEDIUM | 2021-03-22 | 2023-11-07 |
| CVE-2020-27978 json | Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a log... | 7.5 - HIGH | 2020-10-28 | 2022-02-08 |
| CVE-2019-19191 json | Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by ... | 7.8 - HIGH | 2019-11-21 | 2020-01-14 |
| CVE-2018-0489 json | Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mi... | 6.5 - MEDIUM | 2018-02-27 | 2018-03-23 |
| CVE-2018-0486 json | Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mish... | 6.5 - MEDIUM | 2018-01-13 | 2018-02-15 |
| CVE-2017-16853 json | The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.... | Not Provided | 2017-11-16 | 2025-04-20 |
| CVE-2017-16852 json | shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.... | Not Provided | 2017-11-16 | 2025-04-20 |
| CVE-2015-2684 json | Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a cr... | Not Provided | 2015-03-31 | 2026-05-06 |
| CVE-2015-1796 json | The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candida... | Not Provided | 2015-07-08 | 2026-05-06 |
| CVE-2014-3603 json | The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and Op... | 5.9 - MEDIUM | 2019-04-04 | 2019-04-08 |
| CVE-2013-6440 json | The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java bef... | Not Provided | 2014-02-14 | 2026-04-29 |
| CVE-2011-2516 json | Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and po... | Not Provided | 2011-07-11 | 2026-04-29 |
| CVE-2011-1411 json | Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge... | Not Provided | 2011-09-02 | 2026-04-29 |
| CVE-2010-2450 json | The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES priv... | 7.5 - HIGH | 2019-11-07 | 2019-11-13 |
Known software with vulnerabilities from Shibboleth
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Shibboleth | Identify Provider | 3.0.0 |
| Application | Shibboleth | Identity Provider | 2.4.3 |
| Application | Shibboleth | Opensaml | 2.6.1 |
| Application | Shibboleth | Opensaml Java | 2.6.4 |
| Application | Shibboleth | Service Provider | 2.0 |
| Application | Shibboleth | Shibboleth-sp | 1.3.1 |