CVE-2017-16852
published 2017-11-16CVE-2017-16852: shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure…
PriorityP336high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.10%
62.6th percentile
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| shibboleth | service_provider | < 2.6.1 | 2.6.1 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5rhm-55rh-pvvp: shibsp/metadata/DynamicMetadataProvider
ghsa_unreviewed·2022-05-14
CVE-2017-16852 [HIGH] CWE-347 GHSA-5rhm-55rh-pvvp: shibsp/metadata/DynamicMetadataProvider
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.
OSV
CVE-2017-16852: shibsp/metadata/DynamicMetadataProvider
osv·2017-11-16·CVSS 8.1
CVE-2017-16852 [HIGH] CVE-2017-16852: shibsp/metadata/DynamicMetadataProvider
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/881857https://git.shibboleth.net/view/?p=cpp-sp.git%3Ba=commit%3Bh=b66cceb0e992c351ad5e2c665229ede82f261b16https://lists.debian.org/debian-lts-announce/2017/11/msg00025.htmlhttps://shibboleth.net/community/advisories/secadv_20171115.txthttps://www.debian.org/security/2017/dsa-4038https://bugs.debian.org/881857https://git.shibboleth.net/view/?p=cpp-sp.git%3Ba=commit%3Bh=b66cceb0e992c351ad5e2c665229ede82f261b16https://lists.debian.org/debian-lts-announce/2017/11/msg00025.htmlhttps://shibboleth.net/community/advisories/secadv_20171115.txthttps://www.debian.org/security/2017/dsa-4038
2017-11-16
Published