CVE-2021-28963

NameCVE-2021-28963
DescriptionShibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2599-1, DSA-4872-1
NVD severitymedium
Debian Bugs985405

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shibboleth-sp (PTS)buster, buster (security)3.0.4+dfsg1-1+deb10u1fixed
bullseye, sid3.2.1+dfsg1-1fixed
shibboleth-sp2 (PTS)stretch2.6.0+dfsg1-4+deb9u1vulnerable
stretch (security)2.6.0+dfsg1-4+deb9u2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shibboleth-spsourcebuster3.0.4+dfsg1-1+deb10u1DSA-4872-1
shibboleth-spsource(unstable)3.2.1+dfsg1-1985405
shibboleth-sp2sourcestretch2.6.0+dfsg1-4+deb9u2DLA-2599-1
shibboleth-sp2source(unstable)(unfixed)

Notes

https://shibboleth.net/community/advisories/secadv_20210317.txt
https://issues.shibboleth.net/jira/browse/SSPCPP-922
https://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=d1dbebfadc1bdb824fea63843c4c38fa69e54379

Search for package or bug name: Reporting problems