CVE-2017-16853: High severity shibboleth OpenSAML vulnerability

Published Nov 15, 2017
·
Updated

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.

Affected Software

4 affected components
debian/opensaml2
shibboleth OpenSAML<2.6.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0

Event History

Nov 15, 2017
Data Sourced
08:09 PM
SeverityAffected Software
Nov 16, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2017-16853?

CVE-2017-16853 is considered a critical vulnerability due to its failure to perform essential security checks and potential impact on security.

2

How do I fix CVE-2017-16853?

The fix for CVE-2017-16853 involves upgrading to OpenSAML version 2.6.1 or later, which addresses the configuration issues and security checks.

3

What software is affected by CVE-2017-16853?

CVE-2017-16853 affects OpenSAML versions prior to 2.6.1, particularly in its implementation in the Debian operating system.

4

What specific issue does CVE-2017-16853 have regarding security?

CVE-2017-16853 fails to perform critical signature verification and validity checks, leaving systems vulnerable to security risks.

5

Who is responsible for the OpenSAML vulnerability identified as CVE-2017-16853?

The OpenSAML project maintainers are responsible for addressing the vulnerability identified as CVE-2017-16853 and providing updates to mitigate the risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203