{"id":"GHSA-qwwj-qj3f-9hv7","summary":"Improper Authentication in OpenSAML","details":"Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an \"XML Signature wrapping attack.\"","aliases":["CVE-2011-1411"],"modified":"2024-12-07T05:39:37.210445Z","published":"2022-05-17T05:02:41Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-13T17:17:40Z","nvd_published_at":"2011-09-02T23:55:00Z","cwe_ids":["CWE-287"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1411"},{"type":"WEB","url":"http://shibboleth.internet2.edu/secadv/secadv_20110725.txt"},{"type":"WEB","url":"http://www.debian.org/security/2011/dsa-2284"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html"}],"affected":[{"package":{"name":"org.opensaml:opensaml","ecosystem":"Maven","purl":"pkg:maven/org.opensaml/opensaml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.0"},{"fixed":"2.4.3"}]}],"versions":["2.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qwwj-qj3f-9hv7/GHSA-qwwj-qj3f-9hv7.json"}},{"package":{"name":"org.opensaml:opensaml","ecosystem":"Maven","purl":"pkg:maven/org.opensaml/opensaml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0"},{"fixed":"2.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qwwj-qj3f-9hv7/GHSA-qwwj-qj3f-9hv7.json"}}],"schema_version":"1.9.0"}