Ipsilon Project maintains a focused identity and access management platform centered on a single Ipsilon product, which provides federation and single sign-on capabilities in enterprise deployments. The durable signal in its vulnerability profile centers on session-management weaknesses, specifically session-fixation issues that reflect the authentication and token-handling complexity inherent to federated identity systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipsilon Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-8638CRITICAL A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. Thi | Jul 12, 2017 | 9.1 | 29 | NO | NO |
CVE-2015-5216MEDIUM The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remot | Feb 17, 2020 | 6.1 | 17 | NO | NO |
CVE-2015-5215MEDIUM The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not enable auto-escaping, which makes it easi | Feb 17, 2020 | 6.1 | 17 | NO | NO |
CVE-2015-5301MEDIUM providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.2 and 1.1.x before 1.1.1 does not properly check permissions, which allows remote authent | Nov 17, 2015 | 5.5 | 16 | NO | NO |
CVE-2015-5217MEDIUM providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly check permissions to update the SAML2 Service Provider (SP) owner, wh | Nov 17, 2015 | 4.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipsilon Project.
Media articles that mention a CVE ID that affects a product developed by Ipsilon Project — matched by CVE ID, not by vendor name.