Vulnerabilities > Shibboleth > Service Provider > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-22 CVE-2021-28963 Injection vulnerability in multiple products
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
network
low complexity
shibboleth debian CWE-74
5.3
2019-11-07 CVE-2010-2450 Use of Password Hash With Insufficient Computational Effort vulnerability in multiple products
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm.
network
low complexity
shibboleth debian CWE-916
5.0
2015-03-31 CVE-2015-2684 Improper Input Validation vulnerability in multiple products
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
network
low complexity
shibboleth debian CWE-20
4.0