PT-2014-3116 · Shibboleth · Opensaml Java
Publicado
2014-02-14
·
Atualizado
2022-05-13
·
CVE-2013-6440
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Shibboleth OpenSAML-Java versions prior to 2.6.1
Description
The issue allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration. This is due to the expandEntityReferences property being set to true in certain components.
Recommendations
For versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue. As a temporary workaround, consider setting the expandEntityReferences property to false in the affected components, including the BasicParserPool, StaticBasicParserPool, XML Decrypter, and SAML Decrypter.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opensaml Java