Security Advisory

CVE-2014-3603

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-04-04 13:38:16
Last updated 2024-08-06 10:50:17
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.