CVE-2009-3474Opensaml vulnerability

CWE-3105 documents5 sources
Severity
7.5HIGHNVD
EPSS
1.3%
top 20.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29
Latest updateMay 2

Description

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

Debianinternet2/opensaml< 3.0.0-2+3
Debianinternet2/shibboleth-sp< 3.0.2+dfsg1-2+3
NVDinternet2/opensaml2.0, 2.1.0, 2.2.0+2
NVDinternet2/xmltooling4 versions+3
NVDinternet2/shibboleth-sp7 versions+6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-575w-rwc7-4259: OpenSAML 22022-05-02
CVEList
CVE-2009-3474: OpenSAML 22009-09-29
OSV
CVE-2009-3474: OpenSAML 22009-09-29

📋Vendor Advisories

1
Debian
CVE-2009-3474: opensaml - OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 ...2009
CVE-2009-3474 — Internet2 Opensaml vulnerability | cvebase