← Back

CVE-2011-1411

nvd nist
Published: Sep 2, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD

Description

Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

Affected (15)

2 products
Opensaml
Shibboleth Identity Provider
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Shibboleth
Version 2.4.0
Version 2.4.1
Version 2.4.2
Version 2.5.0
Configuration B
11 vulnerable

References (10)

Timeline

No history available yet.