CVE-2023-36661 is a Server-Side Request Forgery (SSRF) vulnerability in Shibboleth XMLTooling before version 3.2.4, impacting products like OpenSAML and Shibboleth Service Provider, including specific Debian packages. This high-severity vulnerability (CVSS 7.5) allows unauthenticated attackers to trigger denial of service by crafting a malicious KeyInfo element. While not officially in CISA's KEV catalog, it has a high FAUCET Risk Score of 99/100 and has been linked to exploitation in the wild, specifically through a Metasploit module targeting Ivanti Connect Secure, indicating active exploitation and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.4CPE matchmatch criteria | cpe:2.3:a:shibboleth:xmltooling:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.