CVE-2023-36661
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
- Affected products
- Astra Linux, Shibboleth Service Provider, Shibboleth Xmltooling-C, Suse, Ubuntu
- Shibboleth Xmltooling
- < 3.2.4
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 2.9% (86th percentile)
- Weakness
- CWE-918
- NVD status
- Modified
- Published
- 2023-06-25
CVE-2023-36661 at NVD
2 known exploits for CVE-2023-36661
Proof-of-concept code and exploit modules indexed by Sploitus