CVE-2011-1411
Published Sep 2, 2011
Last updated 11 years ago
Overview
- Description
- Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:shibboleth:opensaml:2.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "326C4DAA-C2FE-431E-82AE-5260484EBDC4" }, { "criteria": "cpe:2.3:a:shibboleth:opensaml:2.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68F5A4FF-96ED-41CD-A83F-3810B9036037" }, { "criteria": "cpe:2.3:a:shibboleth:opensaml:2.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71772B98-345F-42E0-BBAC-309E24D887B7" }, { "criteria": "cpe:2.3:a:shibboleth:opensaml:2.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7CD6A0B-B78E-4D3C-81E4-27B8E4430F78" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A943122-D2CD-4E2A-A0D5-A3C71B5E62EA", "versionEndIncluding": "2.3.1" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7AAD703-4FB6-456A-B90E-370F3678FD02" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8969B3F6-03A3-471A-A023-A261D36995C3" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4490D05A-8D8E-4445-B404-6B951C50D5F0" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9DEB9670-E47E-4181-8607-7F2E3C59306B" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9288EBA7-5975-4CF6-974B-45A12F2B81DB" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C5D4672-D1D7-41D3-8AAA-3EA180D5DDCB" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45AE00EF-707A-42FE-8673-0F1524C0B368" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A7BEDBC-8026-459D-8A46-2F23311B23A3" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "857E10D3-3701-45CB-AAD7-31D8990A3DE4" }, { "criteria": "cpe:2.3:a:shibboleth:shibboleth-identity-provider:2.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5EC7D93A-FB15-4099-BF63-221704CEBA9B" } ], "operator": "OR" } ] } ]