CVE-2020-27978
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2020
Last modified:
08/02/2022
Description
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:shibboleth:identity_provider:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.4.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page