XML External Entity Vulnerability in Shibboleth OpenSAML-Java
CVE-2013-6440

Currently unrated

Key Information:

Vendor

Shibboleth

Status
Vendor
CVE Published:
14 February 2014

What is CVE-2013-6440?

The BasicParserPool, StaticBasicParserPool, XML Decrypter, and SAML Decrypter components of Shibboleth OpenSAML-Java prior to version 2.6.1 have a vulnerability due to the expandEntityReferences property being set to true. This configuration allows remote attackers to exploit the system by conducting XML External Entity (XXE) attacks through specially crafted XML DOCTYPE declarations, potentially leading to exposure of sensitive information or denial of service.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.