Description
Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4905-1 | shibboleth-sp security update |
EUVD |
EUVD-2021-18701 | Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:10:30.613Z
Reserved: 2021-04-27T00:00:00.000Z
Link: CVE-2021-31826
No data.
Status : Modified
Published: 2021-04-27T04:15:08.550
Modified: 2024-11-21T06:06:18.140
Link: CVE-2021-31826
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD