CVE-2022-24129 PoC — Shibboleth 代码问题漏洞
关联漏洞
标题:
Shibboleth 代码问题漏洞
(CVE-2022-24129)
Description:Shibboleth是英国Shibboleth公司的一套基于Windows平台的开源的SAML协议的Web单点登录系统。 Shibboleth Identity Provider 存在安全漏洞,该漏洞源于 request_uri 参数限制不足,Shibboleth Identity Provider 3.0.4 之前的 OIDC OP 插件允许服务器端请求伪造 (SSRF)。 这允许攻击者与任意第三方 HTTP 服务进行交互。
Description
The Shibboleth Identity Provider OIDC OP plugin before 3.0.4 is vulnerable to server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter, which allows attackers to interact with arbitrary third-party HTTP services.
文件快照
备注
1. 建议优先通过来源进行访问。
2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →