#VU107365 Improper access control in picketlink - CVE-2015-0277
Published: April 10, 2025
picketlink
PicketLink
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to Service Provider (SP) in PicketLink does not ensure that it is a member of an Audience element when an AudienceRestriction is specified. A remote user can log in to other users' accounts via a crafted SAML assertion.