Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Pedro Igor Craveiro

#22261de 56,337
12CVSS total
Vulnerabilidades · 2
Média
2
PT-2015-4558
6.0
2015-08-17
Jboss · Picketlink · CVE-2015-0277
**Name of the Vulnerable Software and Affected Versions** PicketLink versions prior to 2.7.0 **Description** The issue allows remote attackers to log in to other users' accounts via a crafted SAML assertion because the Service Provider (SP) in PicketLink does not ensure that it is a member of an Audience element when an AudienceRestriction is specified. **Recommendations** For versions prior to 2.7.0, update to version 2.7.0 or later to resolve the issue.
PT-2015-7140
6.0
2015-08-17
Jboss · Picketlink · CVE-2015-6254
**Name of the Vulnerable Software and Affected Versions** PicketLink versions prior to 2.7.0 **Description** The issue in PicketLink allows remote attackers to have an unspecified impact. This is due to the Service Provider (SP) and Identity Provider (IdP) not ensuring that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received. **Recommendations** For versions prior to 2.7.0, update to version 2.7.0 or later to resolve the issue.