跳转到帖子

FreeBSD: VID-F7E9A1CC-0931-11EE-94B4-6CC21735F730: xmltooling -- remote resource access

recommended_posts

发布于
  • Members

FreeBSD: VID-F7E9A1CC-0931-11EE-94B4-6CC21735F730: xmltooling -- remote resource access

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
06/12/2023
Created
06/14/2023
Added
06/13/2023
Modified
06/13/2023

Description

Shibboleth consortium reports:

An updated version of the XMLTooling library that is part of the

OpenSAML and Shibboleth Service Provider software is now available

which corrects a server-side request forgery (SSRF) vulnerability.

Including certain legal but "malicious in intent" content in the

KeyInfo element defined by the XML Signature standard will result

in attempts by the SP's shibd process to dereference untrusted

URLs.

While the content of the URL must be supplied within the message

and does not include any SP internal state or dynamic content,

there is at minimum a risk of denial of service, and the attack

could be combined with others to create more serious vulnerabilities

in the future.

Solution(s)

  • freebsd-upgrade-package-xmltooling
  • 查看数 698
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…