Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pedro Igor Craveiro

#20909of 53,633
12Total CVSS
Vulnerabilities · 2
Medium
2
PT-2015-4558
6.0
2015-08-17
Jboss · Picketlink · CVE-2015-0277
**Name of the Vulnerable Software and Affected Versions** PicketLink versions prior to 2.7.0 **Description** The issue allows remote attackers to log in to other users' accounts via a crafted SAML assertion because the Service Provider (SP) in PicketLink does not ensure that it is a member of an Audience element when an AudienceRestriction is specified. **Recommendations** For versions prior to 2.7.0, update to version 2.7.0 or later to resolve the issue.
PT-2015-7140
6.0
2015-08-17
Jboss · Picketlink · CVE-2015-6254
**Name of the Vulnerable Software and Affected Versions** PicketLink versions prior to 2.7.0 **Description** The issue in PicketLink allows remote attackers to have an unspecified impact. This is due to the Service Provider (SP) and Identity Provider (IdP) not ensuring that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received. **Recommendations** For versions prior to 2.7.0, update to version 2.7.0 or later to resolve the issue.