opensaml-core: Signature Forgery in OpenSAML
Published Mar 28, 2025
4.0
MEDIUMCVSS 3.1
EPSS 0.24%
Description
The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).
Affected products
-
- Version 0StatusaffectedConstraints<3.3.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Shibboleth | OpenSAML C++ library | unaffected |
|
No data.
No data.
Logging Subsystem for Red Hat OpenShift
opensaml-core
Fix deferred
Red Hat Fuse 7
opensaml-core
Not affected
Red Hat Integration Camel K 1
opensaml-core
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
opensaml-core
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
opensaml-core
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
org.jboss.eap-jboss-eap-xp
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
opensaml-core
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.jboss.eap-jboss-eap-xp
Not affected
Red Hat Single Sign-On 7
opensaml-core
Not affected
Red Hat build of Apache Camel 4 for Quarkus 3
quarkus-camel-bom
Not affected
Red Hat build of Apache Camel 4 for Quarkus 3
quarkus-cxf-bom
Not affected
Red Hat build of Apache Camel for Spring Boot 4
opensaml-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | opensaml-core | Fix deferred | n/a |
| Red Hat Fuse 7 | opensaml-core | Not affected | n/a |
| Red Hat Integration Camel K 1 | opensaml-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | opensaml-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | opensaml-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | org.jboss.eap-jboss-eap-xp | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | opensaml-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.jboss.eap-jboss-eap-xp | Not affected | n/a |
| Red Hat Single Sign-On 7 | opensaml-core | Not affected | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | quarkus-camel-bom | Not affected | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | quarkus-cxf-bom | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | opensaml-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-31335 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2355681 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-14769 Advisory
- https://git.shibboleth.net/view/?p=cpp-opensaml.git;a=commit;h=22a610b322e2178abd03e97cdbc8fb50b45efaee
- https://lists.debian.org/debian-security-announce/2025/msg00041.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-31335
- https://shibboleth.atlassian.net/browse/CPPOST-126
- https://shibboleth.net/community/advisories/secadv_20250313.txt
- https://www.cve.org/CVERecord?id=CVE-2025-31335
Change history (0)
No recorded changes yet.