Shibboleth Service Provider
By the Year
In 2024 there have been 0 vulnerabilities in Shibboleth Service Provider . Service Provider did not have any published security vulnerabilities last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 0 | 0.00 |
2023 | 0 | 0.00 |
2022 | 0 | 0.00 |
2021 | 2 | 6.40 |
2020 | 0 | 0.00 |
2019 | 1 | 7.80 |
2018 | 0 | 0.00 |
It may take a day or so for new Service Provider vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Shibboleth Service Provider Security Vulnerabilities
Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature
CVE-2021-31826
7.5 - High
- April 27, 2021
Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.
NULL Pointer Dereference
Shibboleth Service Provider before 3.2.1
CVE-2021-28963
5.3 - Medium
- March 22, 2021
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
Injection
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file
CVE-2019-19191
7.8 - High
- November 21, 2019
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.
insecure temporary file
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Shibboleth Service Provider or by Shibboleth? Click the Watch button to subscribe.