← Back to CVE List

CVE-2020-27978

Published: 2020-10-28T15:15Z
Last Modified: 2024-11-21T05:22Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt