Security Bypass in OpenSAML and XMLTooling Affecting Shibboleth Service Provider
CVE-2009-3474

Currently unrated

Key Information:

Vendor

Internet2

Vendor
CVE Published:
29 September 2009

What is CVE-2009-3474?

A security bypass vulnerability exists in OpenSAML and XMLTooling due to improper handling of the KeyDescriptor element's Use attribute. This flaw allows remote attackers to misuse certificates designated for a single purpose, enabling the same certificate to be employed for both signing and encryption. Consequently, this can compromise the intended security mechanisms of applications relying on these libraries.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.