USN-8768-1: Shibboleth vulnerability
AI summary · glm-5.3
Ubuntu patches Shibboleth SQL injection in the ODBC storage plugin allowing remote attackers to extract sensitive information.
Ubuntu security notice USN-8768-1 fixes a Shibboleth vulnerability discovered by Florian Stuhlmann. The software incorrectly escaped input when using the ODBC storage plugin, allowing a remote attacker to perform SQL injection attacks and obtain sensitive information. Users are advised to update the Shibboleth package.
- Improper input escaping in ODBC storage plugin enables SQL injection
- Remote attackers could read sensitive database information
Full article
Florian Stuhlmann discovered that Shibboleth incorrectly escaped input when using the ODBC storage plugin. A remote attacker could possibly use this issue to perform SQL injection attacks and obtain sensitive information.
This source does not provide full text. Read it at ubuntu.com.