MEDIUM · 6.0

CVE-2015-0277

The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to oth...

Vulnerability Description

The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to other users' accounts via a crafted SAML assertion. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6254 for lack of validation for the Destination attribute in a Response element in a SAML assertion.

CVSS Score

6.0

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
PicketlinkPicketlink<= 2.6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0277?

CVE-2015-0277 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to oth...

How severe is CVE-2015-0277?

CVE-2015-0277 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0277?

Check the references section above for vendor advisories and patch information. Affected products include: Picketlink Picketlink.