FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Shibboleth Service Provider -- SQL injection vulnerability in ODBC plugin

Affected packages
shibboleth-sp < 3.5.1

Details

VuXML ID 9f9b0b37-88fa-11f0-90a2-6cc21735f730
Discovery 2025-09-03
Entry 2025-09-03

Internet2 reports:

The Shibboleth Service Provider includes a storage API usable for a number of different use cases such as the session cache, replay cache, and relay state management. An ODBC extension plugin is provided with some distributions of the software (notably on Windows).

A SQL injection vulnerability was identified in some of the queries issued by the plugin, and this can be creatively exploited through specially crafted inputs to exfiltrate information stored in the database used by the SP.

References

URL https://shibboleth.net/community/advisories/secadv_20250903.txt