CVE-2017-16853

Publication date 16 November 2017

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

8.1 · High

Score breakdown

Description

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.

Status

Package Ubuntu Release Status
opensaml2 18.10 cosmic
Not affected
18.04 LTS bionic
Not affected
17.10 artful
Fixed 2.6.0-4+deb9u1build0.17.10.1
17.04 zesty
Fixed 2.6.0-4+deb9u1build0.17.04.1
16.04 LTS xenial
Fixed 2.5.5-1ubuntu0.1
14.04 LTS trusty
Fixed 2.5.3-2+deb8u2build0.14.04.1

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.1 · High

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities