CVE-2023-36661: SSRF
Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/xmltoolingto a version that resolves this vulnerability.Fixed in 3.2.4-1 - Upgrade
Upgrade
ubuntu/xmltoolingto a version that resolves this vulnerability.Fixed in 1.5.6-2ubuntu0.3+ - Upgrade
Upgrade
debian/xmltoolingto a version that resolves this vulnerability.Fixed in 3.0.4-1+deb10u2Fixed in 3.2.0-3+deb11u1Fixed in 3.2.3-1+deb12u1Fixed in 3.2.4-2 - Upgrade
Upgrade
Shibboleth XMLToolingto a version that resolves this vulnerability.Fixed in 3.2.4
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-36661.
What is the severity of CVE-2023-36661?
The severity of CVE-2023-36661 is high.
Which software is affected by CVE-2023-36661?
Shibboleth XMLTooling before version 3.2.4, used in OpenSAML and Shibboleth Service Provider, is affected by CVE-2023-36661.
How can the vulnerability be fixed?
The vulnerability can be fixed by updating to a patched version, such as Shibboleth Service Provider 3.4.1.3 on Windows.
Where can I find more information about CVE-2023-36661?
You can find more information about CVE-2023-36661 in the following references: [Link 1](https://shibboleth.net/community/advisories/secadv_20230612.txt), [Link 2](https://www.debian.org/security/2023/dsa-5432), [Link 3](https://launchpad.net/bugs/cve/CVE-2023-36661).