UBUNTU-CVE-2021-28963
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-28963
UBUNTU-CVE-2021-28963
Summary:
Details: Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
References: https://ubuntu.com/security/CVE-2021-28963, https://shibboleth.net/community/advisories/secadv_20210317.txt, https://issues.shibboleth.net/jira/browse/SSPCPP-922, https://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=d1dbebfadc1bdb824fea63843c4c38fa69e54379, https://bugs.debian.org/985405, https://www.debian.org/security/2021/dsa-4872, https://ubuntu.com/security/notices/USN-4925-1, https://www.cve.org/CVERecord?id=CVE-2021-28963
Affected packages
Package
Name: shibboleth-sp2
Purl: pkg:deb/ubuntu/shibboleth-sp2?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
