Back

CRITICAL

ipsilon: DoS via logging out all open SAML2 sessions

Published Jul 12, 2017

Description

A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."

Affected products

Remediation

No remediation recorded yet.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 12, 2017
Updated Aug 6, 2024
Reserved Oct 12, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 21, 2016
GHSA-376M-3RM2-9JM6