CVE-2017-16852: High severity shibboleth Service Provider vulnerability
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16852?
CVE-2017-16852 has a severity rating that indicates it can lead to critical security issues due to improper configuration and lack of signature verification.
How do I fix CVE-2017-16852?
To fix CVE-2017-16852, you should upgrade the Shibboleth Service Provider to version 2.6.1 or later.
What systems are affected by CVE-2017-16852?
CVE-2017-16852 affects Shibboleth Service Provider versions prior to 2.6.1 on various platforms including Debian 8.0 and 9.0.
What kind of vulnerabilities does CVE-2017-16852 exploit?
CVE-2017-16852 exploits vulnerabilities related to the lack of signature verification and proper security checks in the Dynamic MetadataProvider.
Is there a known workaround for CVE-2017-16852?
There are no widely documented workarounds for CVE-2017-16852, so upgrading to a secure version is the recommended action.