Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
Published March 22, 2021.
Debian Debian Linux
Shibboleth Service Provider