Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-28963
Description:Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
Test IDs: 1.3.6.1.4.1.25623.1.0.844912   1.3.6.1.4.1.25623.1.0.704872   1.3.6.1.4.1.25623.1.0.892599  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-28963
https://bugs.debian.org/985405
https://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=d1dbebfadc1bdb824fea63843c4c38fa69e54379
https://issues.shibboleth.net/jira/browse/SSPCPP-922
https://shibboleth.net/community/advisories/secadv_20210317.txt
https://www.debian.org/security/2021/dsa-4872




© 1998-2025 E-Soft Inc. All rights reserved.