CVE-2021-28963
22.03.2021, 08:15
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
| Vendor | Product | Version |
|---|---|---|
| shibboleth | service_provider | 𝑥 < 3.2.1 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| shibboleth-sp |
| ||||||||||||||||||||||||
| shibboleth-sp2 |
|
References