CVE-2014-3603
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or…
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-297
- Affected
- shibboleth/identity provider · shibboleth/opensaml java
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/60816Permissions Required, Third Party Advisory
- http://shibboleth.net/community/advisories/secadv_20140813.txtVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1131823Exploit, Issue Tracking, Third Party Advisory
- http://secunia.com/advisories/60816Permissions Required, Third Party Advisory
- http://shibboleth.net/community/advisories/secadv_20140813.txtVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1131823Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.