An attacker can exploit this issue to bypass certain security restrictions and gain access to sensitive areas of application to perform unauthorized actions; this may aid in launching further attacks.Shibboleth authentication versions prior to 6.x-4.0-rc3 are vulnerable.
Vendor Status:
Currently we are not aware of any vendor-supplied patches