|
|
Log in / Subscribe / Register

opensaml-java: missing host name verification

Package(s):opensaml-java CVE #(s):CVE-2014-3603
Created:August 7, 2015 Updated:August 12, 2015
Description: From the Red Hat bugzilla:

It was discovered that HttpResource and FileBackedHttpResource implementations in OpenSAML Java and Shibboleth IdP did not enable hostname verification when using TLS connections. Additionally, OpenSAML Java makes use of Jakarta Commons HttpClient version 3.x, which does not perform verification of the server hostname against the server's X.508 certificate (CVE-2012-5783). This flaw can be exploited by a Man-in-the-middle (MITM) attack, where the attacker can spoof a valid certificate using a specially crafted subject.

Alerts:
Fedora FEDORA-2015-10175 opensaml-java-openws 2015-08-07
Fedora FEDORA-2015-10235 opensaml-java-openws 2015-08-07
Fedora FEDORA-2015-10175 opensaml-java 2015-08-07
Fedora FEDORA-2015-10235 opensaml-java 2015-08-07

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds