CVE-2017-16853: High severity shibboleth OpenSAML vulnerability
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16853?
CVE-2017-16853 is considered a critical vulnerability due to its failure to perform essential security checks and potential impact on security.
How do I fix CVE-2017-16853?
The fix for CVE-2017-16853 involves upgrading to OpenSAML version 2.6.1 or later, which addresses the configuration issues and security checks.
What software is affected by CVE-2017-16853?
CVE-2017-16853 affects OpenSAML versions prior to 2.6.1, particularly in its implementation in the Debian operating system.
What specific issue does CVE-2017-16853 have regarding security?
CVE-2017-16853 fails to perform critical signature verification and validity checks, leaving systems vulnerable to security risks.
Who is responsible for the OpenSAML vulnerability identified as CVE-2017-16853?
The OpenSAML project maintainers are responsible for addressing the vulnerability identified as CVE-2017-16853 and providing updates to mitigate the risks.