Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libapache2-mod-shib" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libapache2-mod-shib-dbgsym" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libapache2-mod-shib2" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libshibsp-dev" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libshibsp-doc" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libshibsp-plugins" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libshibsp-plugins-dbgsym" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libshibsp8" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "libshibsp8-dbgsym" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "shibboleth-sp-common" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "shibboleth-sp-utils" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "shibboleth-sp-utils-dbgsym" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "shibboleth-sp2-common" }, { "binary_version": "3.0.4+dfsg1-1ubuntu0.1", "binary_name": "shibboleth-sp2-utils" } ] }