Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2011-09-02 16:55
Updated : 2013-10-10 20:34
NVD link : CVE-2011-1411
Mitre link : CVE-2011-1411
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
shibboleth
- shibboleth-identity-provider
- opensaml