Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2011-09-02 23:55
Updated : 2013-10-11 03:34
NVD link : CVE-2011-1411
Mitre link : CVE-2011-1411
CVE.ORG link : CVE-2011-1411
JSON object : View
Products Affected
shibboleth
- opensaml
- shibboleth-identity-provider
CWE
CWE-287
Improper Authentication