CVE-2013-6440

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:internet2:opensaml:2.0:*:*:*:*:*:*:*
cpe:2.3:a:internet2:opensaml:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:internet2:opensaml:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:*:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:shibboleth:opensaml:2.5.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:59

Type Values Removed Values Added
References () http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and-the-dangers-of-saml-xml - () http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and-the-dangers-of-saml-xml -
References () http://rhn.redhat.com/errata/RHSA-2014-0170.html - () http://rhn.redhat.com/errata/RHSA-2014-0170.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0171.html - () http://rhn.redhat.com/errata/RHSA-2014-0171.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0172.html - () http://rhn.redhat.com/errata/RHSA-2014-0172.html -
References () http://rhn.redhat.com/errata/RHSA-2014-0195.html - () http://rhn.redhat.com/errata/RHSA-2014-0195.html -
References () http://shibboleth.net/community/advisories/secadv_20131213.txt - () http://shibboleth.net/community/advisories/secadv_20131213.txt -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1043332 - () https://bugzilla.redhat.com/show_bug.cgi?id=1043332 -
References () https://www.oracle.com/security-alerts/cpujan2022.html - () https://www.oracle.com/security-alerts/cpujan2022.html -

Information

Published : 2014-02-14 15:55

Updated : 2024-11-21 01:59


NVD link : CVE-2013-6440

Mitre link : CVE-2013-6440

CVE.ORG link : CVE-2013-6440


JSON object : View

Products Affected

shibboleth

  • opensaml

internet2

  • opensaml
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor