Security Bypass in OpenSAML and XMLTooling Affecting Shibboleth Service Provider
CVE-2009-3474
Currently unrated
Key Information:
- Vendor
Internet2
- Vendor
- CVE Published:
- 29 September 2009
What is CVE-2009-3474?
A security bypass vulnerability exists in OpenSAML and XMLTooling due to improper handling of the KeyDescriptor element's Use attribute. This flaw allows remote attackers to misuse certificates designated for a single purpose, enabling the same certificate to be employed for both signing and encryption. Consequently, this can compromise the intended security mechanisms of applications relying on these libraries.
