CVE-2017-16853
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- shibboleth/opensaml · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/101898Third Party Advisory, VDB Entry
- https://bugs.debian.org/881856Issue Tracking, Third Party Advisory
- https://git.shibboleth.net/view/?p=cpp-opensaml.git%3Ba=commit%3Bh=6182b0acf2df670e75423c2ed7afe6950ef11c9d
- https://lists.debian.org/debian-lts-announce/2017/11/msg00024.html
- https://shibboleth.net/community/advisories/secadv_20171115.txtIssue Tracking, Vendor Advisory
- https://www.debian.org/security/2017/dsa-4039Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/101898Third Party Advisory, VDB Entry
- https://bugs.debian.org/881856Issue Tracking, Third Party Advisory
- https://git.shibboleth.net/view/?p=cpp-opensaml.git%3Ba=commit%3Bh=6182b0acf2df670e75423c2ed7afe6950ef11c9d
- https://lists.debian.org/debian-lts-announce/2017/11/msg00024.html
- https://shibboleth.net/community/advisories/secadv_20171115.txtIssue Tracking, Vendor Advisory
- https://www.debian.org/security/2017/dsa-4039Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.