GHSA-78fq-w796-q537
Dashboard / Vulnerabilities / GHSA-78fq-w796-q537
Summary: Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML
Details: The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-1796, https://shibboleth.net/community/advisories/secadv_20150225.txt, http://rhn.redhat.com/errata/RHSA-2015-1176.html, http://rhn.redhat.com/errata/RHSA-2015-1177.html
Affected packages
Package
Name: org.opensaml:opensaml
Purl: pkg:maven/org.opensaml/opensaml
Affected ranges
Type: ECOSYSTEM
Events:
