Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
{ "binaries": [ { "binary_name": "libapache2-mod-shib2", "binary_version": "2.5.3+dfsg-2.1build1" }, { "binary_name": "libshibsp-dev", "binary_version": "2.5.3+dfsg-2.1build1" }, { "binary_name": "libshibsp-plugins", "binary_version": "2.5.3+dfsg-2.1build1" }, { "binary_name": "libshibsp6", "binary_version": "2.5.3+dfsg-2.1build1" }, { "binary_name": "shibboleth-sp2-common", "binary_version": "2.5.3+dfsg-2.1build1" }, { "binary_name": "shibboleth-sp2-schemas", "binary_version": "2.5.3+dfsg-2.1build1" }, { "binary_name": "shibboleth-sp2-utils", "binary_version": "2.5.3+dfsg-2.1build1" } ] }
{ "binaries": [ { "binary_name": "libapache2-mod-shib2", "binary_version": "2.6.1+dfsg1-2" }, { "binary_name": "libshibsp-dev", "binary_version": "2.6.1+dfsg1-2" }, { "binary_name": "libshibsp-plugins", "binary_version": "2.6.1+dfsg1-2" }, { "binary_name": "libshibsp7", "binary_version": "2.6.1+dfsg1-2" }, { "binary_name": "shibboleth-sp2-common", "binary_version": "2.6.1+dfsg1-2" }, { "binary_name": "shibboleth-sp2-utils", "binary_version": "2.6.1+dfsg1-2" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libapache2-mod-shib", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" }, { "binary_name": "libapache2-mod-shib2", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" }, { "binary_name": "libshibsp-dev", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" }, { "binary_name": "libshibsp-plugins", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" }, { "binary_name": "libshibsp8", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" }, { "binary_name": "shibboleth-sp-common", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" }, { "binary_name": "shibboleth-sp-utils", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" }, { "binary_name": "shibboleth-sp2-common", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" }, { "binary_name": "shibboleth-sp2-utils", "binary_version": "3.0.4+dfsg1-1ubuntu0.1" } ] }
{ "binaries": [ { "binary_name": "libapache2-mod-shib", "binary_version": "3.3.0+dfsg1-1" }, { "binary_name": "libshibsp-dev", "binary_version": "3.3.0+dfsg1-1" }, { "binary_name": "libshibsp-plugins", "binary_version": "3.3.0+dfsg1-1" }, { "binary_name": "libshibsp10", "binary_version": "3.3.0+dfsg1-1" }, { "binary_name": "shibboleth-sp-common", "binary_version": "3.3.0+dfsg1-1" }, { "binary_name": "shibboleth-sp-utils", "binary_version": "3.3.0+dfsg1-1" } ] }