CVE-2022-24129: SSRF
The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the requesturi parameter. This allows attackers to interact with arbitrary third-party HTTP services.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24129?
CVE-2022-24129 is a vulnerability that affects the OIDC OP plugin before version 3.0.4 for Shibboleth Identity Provider.
What is the severity of CVE-2022-24129?
The severity of CVE-2022-24129 is high with a severity value of 8.2.
How does CVE-2022-24129 impact the Shibboleth Identity Provider?
CVE-2022-24129 allows server-side request forgery (SSRF), which enables attackers to interact with arbitrary third-party HTTP services.
How can I fix CVE-2022-24129?
To fix CVE-2022-24129, upgrade the OIDC OP plugin to version 3.0.4 or newer for the Shibboleth Identity Provider.
Where can I find more information about CVE-2022-24129?
You can find more information about CVE-2022-24129 in the official Shibboleth advisories and the GitHub advisory.