LWN.net Logo

shibboleth-sp: cross-site scripting

Package(s):shibboleth-sp CVE #(s):CVE-2009-3300
Created:December 8, 2009 Updated:December 9, 2009
Description: From the Debian advisory: Matt Elder discovered that Shibboleth, a federated web single sign-on system is vulnerable to script injection through redirection URLs. More details can be found in the Shibboleth advisory at http://shibboleth.internet2.edu/secadv/secadv_20091104.txt.
Alerts:
Debian DSA-1947-1 2009-12-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds