opensaml-java: missing host name verification
| Package(s): | opensaml-java |
CVE #(s): | CVE-2014-3603
|
| Created: | August 7, 2015 |
Updated: | August 12, 2015 |
| Description: |
From the Red Hat bugzilla:
It was discovered that HttpResource and FileBackedHttpResource implementations in OpenSAML Java and Shibboleth IdP did not enable hostname verification when using TLS connections. Additionally, OpenSAML Java makes use of Jakarta Commons HttpClient version 3.x, which does not perform verification of the server hostname against the server's X.508 certificate (CVE-2012-5783). This flaw can be exploited by a Man-in-the-middle (MITM) attack, where the attacker can spoof a valid certificate using a specially crafted subject. |
| Alerts: |
|