SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3603

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or…

MEDIUM 5.9EPSS 0.84%

Does this matter?

Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.

Description

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.84% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-297
Affected
shibboleth/identity provider · shibboleth/opensaml java
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.