CVE-2014-3603
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected (2)
Products: Shibboleth: Identity Provider, Opensaml Java
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.4.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.2 |
References (6)
Source: secalert@redhat.com
Permissions RequiredThird Party Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Timeline
No history available yet.