Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Shibboleth 安全漏洞
Vulnerability Description
Shibboleth是英国Shibboleth公司的一套基于Windows平台的开源的SAML协议的Web单点登录系统。 Shibboleth SP 2.0版本中的keygen.sh脚本存在安全漏洞,该漏洞源于使用OpenSSL生成的DES私钥为全局可读。攻击者可利用该漏洞获取信息。
CVSS Information
N/A
Vulnerability Type
N/A