Shibboleth Identity Provider Security Advisory [19 September 2014]

Cantor, Scott cantor.2 at osu.edu
Fri Sep 19 09:40:21 EDT 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Shibboleth Identity Provider Security Advisory [19 September 2014]

Shibboleth Identity Provider and OpenSAML-J HTTPS and LDAPS Connections
Do Not Perform Proper Hostname Verification
=======================================================================

OpenSAML-J and the Shibboleth IdP contain various components which make
connections to HTTP and LDAP servers, including HTTP configuration
resources, HTTP-based metadata providers, and LDAP authentication and
data connectors.

When used with an HTTPS or LDAPS scheme, these components are
susceptible to a 'Man in the Middle Attack' due to a flaw in the
hostname  verification used with SSL/TLS if a specially-crafted
server-side certificate is used. The lack of proper hostname
verification means that while the connection between the client
and HTTPS/LDAPS server is encrypted, the client may not have correctly
verified that it is actually communicating with the intended HTTPS or
LDAPS server.

For technical details about the nature of the vulnerability, see the
relevant CVEs listed below.

This issue is a follow-on to an earlier Shibboleth advisory issued on
August 13, and assigned CVE-2014-3603. The fix made at that time is
related to, but separate from this vulnerability, which was discovered
just after that patch was released.

The scope of this problem has now expanded beyond just use of the
HttpResource and FileBackedHttpResource features of the IdP to also
include LDAP connectivity via LDAPS for both authentication and
attribute resolution. It also affects all HTTP-based meadata providers,
although we have always strongly recommended the use of signature
checking when consuming metadata, which mitigates that issue.

Finally, please note that the Shibboleth Project has addressed the
not-yet-commons-ssl vulnerability in CVE-2014-2604 with a different
fix that does not involve updating the library version used. This is
due to incompatible changes made to that library that make the newer
version unusable by the project without further modifications.

Affected Versions
=================
Versions of OpenSAML Java < 2.6.3

Versions of the Identity Provider < 2.4.2


Recommendations
===============
IdP users: Upgrade to IdP 2.4.2 or greater.

OpenSAML users: Upgrade to OpenSAML Java 2.6.3 or greater.

References
==========
CVE-2014-3604
Not Yet Commons SSL: Hostname verification susceptible to MITM attack

CVE-2014-3607
vtldap/ldaptive: Hostname verification susceptible to MITM attack

URL for this Security Advisory
http://shibboleth.net/community/advisories/secadv_20140919.txt


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUG34ZAAoJEDeLhFQCJ3liVewP/A90qic6+vAyn9JqNaP+3eSB
qUhOOlpdHOOZ8ZQAS1fv8d+pVCuguBS74wGYU6pAgqvcD3cTfMyNngaruKI7iIhP
aWzi0Yu+Ijya7XDYDPGwtATlaInxm5gzmau0N3/rgVs9yQ1yHXET34jeB0CWtUJL
mNKyx5pnysq0DpXHHElHpe+3ySODsktKaivIVCwVqqywaHPMwo8inlt0Dymr1msl
okRzbqHdrxh2RRueGdagfsQ0L8rxnbTCcCjbVfprUDKnwtfXUISiYTk+SdDFrrS6
nLuTEsoADBVKtwvaKp1+5tRJevgA6LfKdrtPoTGHdVZx/I2lWDWjdek39vkKq+Gm
izX4h5POlUD7zMedR3icV4hFbZnDoCHfmKfLE/b+IK4vhjPuKe9xbwyLyPMTLDO0
7oGIUnhV0Wsj31CvZf8ueks5xtcwwEN5jvt53vqsadNxbyv6PHzI/Eoh/oQ8mN3r
9EnS1WFbZekGGortO5vJXQPaK82w82nnv6vn8ifJewi35MSmt+IFgvbYmYl75noP
+vJNJt/Fn6Ugp8OEsF3UkXpIkQtNFBUgCj9HkCn4Q1qGTaPfGqFZzwiMTsSbOqED
fBn2ihAMgBe8n+U6jJ2XVATHsK+LVPj8Qq41e3C2TVBDb8nM7BVAYY6dqba18vE6
UVgS5L+8pKxYoXuZCJ1Y
=0XeM
-----END PGP SIGNATURE-----






More information about the announce mailing list