CVE-2015-6254
PicketLink <2.7.0 - Info Disclosure
Title source: llmDescription
The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.
Exploits (2)
nomisec
STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2015-6254-picketlink-bindings-vulnerable
nomisec
STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2015-6254-picketlink-bindings-vulnerable
References (6)
Scores
EPSS
0.0070
EPSS Percentile
72.0%
Details
CWE
CWE-17
Status
published
Products (1)
picketlink/picketlink
< 2.6.0
Published
Aug 17, 2015
Tracked Since
Feb 18, 2026