CVE-2011-1411
02.09.2011, 23:55
Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."Enginsight
Vendor | Product | Version |
---|---|---|
shibboleth | opensaml | 2.4.0 |
shibboleth | opensaml | 2.4.1 |
shibboleth | opensaml | 2.4.2 |
shibboleth | opensaml | 2.5.0 |
shibboleth | shibboleth-identity-provider | 𝑥 ≤ 2.3.1 |
shibboleth | shibboleth-identity-provider | 2.0.0 |
shibboleth | shibboleth-identity-provider | 2.1.0 |
shibboleth | shibboleth-identity-provider | 2.1.1 |
shibboleth | shibboleth-identity-provider | 2.1.2 |
shibboleth | shibboleth-identity-provider | 2.1.3 |
shibboleth | shibboleth-identity-provider | 2.1.4 |
shibboleth | shibboleth-identity-provider | 2.1.5 |
shibboleth | shibboleth-identity-provider | 2.2.0 |
shibboleth | shibboleth-identity-provider | 2.2.1 |
shibboleth | shibboleth-identity-provider | 2.3.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References