Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Shibboleth 代码问题漏洞
Vulnerability Description
Shibboleth是英国Shibboleth公司的一套基于Windows平台的开源的SAML协议的Web单点登录系统。 Shibboleth XMLTooling 3.2.4 版本之前存在安全漏洞,该漏洞源于通过特制的 KeyInfo 元素造成服务器端请求伪造(SSRF)。
CVSS Information
N/A
Vulnerability Type
N/A