Josso is an open-source single sign-on platform for Java environments that provides centralized identity and authentication services to downstream applications. Its vulnerability profile centers on the Java Open Single Sign-On Project and reflects durable authentication-related weaknesses that are inherent to the credential-handling and session-management responsibilities of identity platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Josso over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5352MEDIUM Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signat | Oct 9, 2012 | 5.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Josso.
Media articles that mention a CVE ID that affects a product developed by Josso — matched by CVE ID, not by vendor name.