Junglewise Threat Intelligence

CVE-2014-3603: Improper Validation of Certificate with Host Mismatch in Shibboleth Identity Provider and OpenSAML Java

CVE-2014-3603 · Severity: low · CVSS 3 · Published 2022-05-14

Technologies: org.opensaml:opensaml (Maven), edu.internet2.middleware:shibboleth-identityprovider (Maven). Vendors: Maven.

Executive brief

Improper Validation of Certificate with Host Mismatch in Shibboleth Identity Provider and OpenSAML Java

Affected products

  • Maven org.opensaml:opensaml
  • Maven edu.internet2.middleware:shibboleth-identityprovider

Related threats