PT-2014-3116 · Shibboleth · Opensaml Java

Publicado

2014-02-14

·

Atualizado

2022-05-13

·

CVE-2013-6440

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Shibboleth OpenSAML-Java versions prior to 2.6.1
Description The issue allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration. This is due to the expandEntityReferences property being set to true in certain components.
Recommendations For versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue. As a temporary workaround, consider setting the expandEntityReferences property to false in the affected components, including the BasicParserPool, StaticBasicParserPool, XML Decrypter, and SAML Decrypter.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6440
GHSA-V723-58JV-2QC4
RHSA-2014:0170
RHSA-2014:0171

Produtos afetados

Opensaml Java