CVE-2015-6254

Severity CVSS v4.0:
Pending analysis
Type:
CWE-17 Code Errors
Publication date:
17/08/2015
Last modified:
12/04/2025

Description

The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:picketlink:picketlink:*:cr5:*:*:*:*:*:* 2.6.0 (including)