CVE-2021-28963: Medium severity shibboleth vulnerability
Published Mar 22, 2021
·Updated
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
Affected Software
2 affected components
shibboleth Service Provider<3.2.1
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Mar 22, 2021
CVE Published
via MITRE·07:02 AM
Data Sourced
via MITRE·07:02 AM
Description
Frequently Asked Questions
1
What is CVE-2021-28963?
CVE-2021-28963 is a vulnerability in the Shibboleth Service Provider before version 3.2.1 that allows content injection due to template generation using attacker-controlled parameters.
2
What is the severity of CVE-2021-28963?
The severity of CVE-2021-28963 is medium with a CVSS score of 5.3.
3
How does CVE-2021-28963 affect Shibboleth Service Provider?
CVE-2021-28963 affects Shibboleth Service Provider versions up to 3.2.1, allowing content injection through the use of attacker-controlled parameters in template generation.
4
How does CVE-2021-28963 impact Debian Linux?
CVE-2021-28963 impacts Debian Linux version 10.0.
5
Is there a fix for CVE-2021-28963?
Yes, the fix for CVE-2021-28963 is available with the release of Shibboleth Service Provider version 3.2.1.