|
|
| |
|
| |
shibboleth-sp: cross-site scripting
| Package(s): | shibboleth-sp |
CVE #(s): | CVE-2009-3300
|
| Created: | December 8, 2009 |
Updated: | December 9, 2009 |
| Description: |
From the Debian advisory:
Matt Elder discovered that Shibboleth, a federated web single sign-on
system is vulnerable to script injection through redirection URLs. More
details can be found in the Shibboleth advisory at
http://shibboleth.internet2.edu/secadv/secadv_20091104.txt.
|
| Alerts: |
|
( Log in to post comments)
|
|
|