CVE-2020-27978: High severity shibboleth vulnerability
Published Oct 28, 2020
·Updated
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session.
Affected Software
1 affected component
shibboleth Identity Provider>=3.0.0<3.4.6
Event History
Oct 28, 2020
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Shibboleth Identify Provider?
The vulnerability ID for Shibboleth Identify Provider is CVE-2020-27978.
2
What is the severity of CVE-2020-27978?
The severity of CVE-2020-27978 is high with a CVSS score of 7.5.
3
How does CVE-2020-27978 affect Shibboleth Identify Provider?
CVE-2020-27978 is a denial of service flaw that can cause Java heap exhaustion in Shibboleth Identify Provider.
4
How can a remote unauthenticated attacker exploit CVE-2020-27978?
A remote unauthenticated attacker can exploit CVE-2020-27978 by causing a login flow to trigger Java heap exhaustion.
5
How can I fix CVE-2020-27978?
To fix CVE-2020-27978, you should upgrade Shibboleth Identify Provider to version 3.4.6 or later.