{ "schema_version": "1.4.0", "id": "GHSA-rqpx-m7mv-mxxf", "modified": "2022-05-24T17:48:57Z", "published": "2022-05-24T17:48:57Z", "aliases": [ "CVE-2021-31826" ], "details": "Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31826" }, { "type": "WEB", "url": "https://bugs.debian.org/987608" }, { "type": "WEB", "url": "https://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=5a47c3b9378f4c49392dd4d15189b70956f9f2ec" }, { "type": "WEB", "url": "https://issues.shibboleth.net/jira/browse/SSPCPP-927" }, { "type": "WEB", "url": "https://shibboleth.net/community/advisories/secadv_20210426.txt" }, { "type": "WEB", "url": "https://www.debian.org/security/2021/dsa-4905" } ], "database_specific": { "cwe_ids": [ "CWE-476" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-04-27T04:15:00Z" } }