Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Shibboleth 资源管理错误漏洞
Vulnerability Description
Shibboleth是英国Shibboleth公司的一套基于Windows平台的开源的SAML协议的Web单点登录系统。 Shibboleth Identify Provider 3.x系列3.4.6之前版本存在安全漏洞,该漏洞源于有拒绝服务缺陷。由于在Java Servlet容器会话中创建对象,远程未经身份验证的攻击者可利用该漏洞可能导致登录流触发Java堆耗尽。
CVSS Information
N/A
Vulnerability Type
N/A