Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenSAML-Java ParserPool和Decrypter XML外部实体注入漏洞
Vulnerability Description
Shibboleth Shibboleth OpenSAML-Java是英国Shibboleth公司的一个使用Java语言编写的开源且用于实现SAML(Security Assertion Markup Language,安全断言标记语言)的库。 Shibboleth OpenSAML-Java 2.6.1之前的版本中的(1)BasicParserPool,(2)StaticBasicParserPool,(3)XML Decrypter,(4)SAML Decrypter中存在安全漏洞,该漏洞源于程序设
CVSS Information
N/A
Vulnerability Type
N/A