CVE-2009-3474
OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.54% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- internet2/opensaml · internet2/xmltooling · internet2/shibboleth-sp
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/36855Vendor Advisory
- http://secunia.com/advisories/36868Vendor Advisory
- http://secunia.com/advisories/36876Vendor Advisory
- http://shibboleth.internet2.edu/secadv/secadv_20090817a.txtPatch, Vendor Advisory
- http://www.debian.org/security/2009/dsa-1895Patch
- http://www.debian.org/security/2009/dsa-1896Patch
- http://www.securityfocus.com/bid/36516Patch
- https://bugs.internet2.edu/jira/browse/CPPOST-28
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53474
- http://secunia.com/advisories/36855Vendor Advisory
- http://secunia.com/advisories/36868Vendor Advisory
- http://secunia.com/advisories/36876Vendor Advisory
- http://shibboleth.internet2.edu/secadv/secadv_20090817a.txtPatch, Vendor Advisory
- http://www.debian.org/security/2009/dsa-1895Patch
- http://www.debian.org/security/2009/dsa-1896Patch
- http://www.securityfocus.com/bid/36516Patch
- https://bugs.internet2.edu/jira/browse/CPPOST-28
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53474
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.