Shibboleth Service Provider Security Advisory [2018-01-12]

Cantor, Scott cantor.2 at osu.edu
Tue Jan 16 12:21:04 EST 2018


As a follow up to this issue. I had no idea they were going to this, but the company that found the exploit decided to publish it with full details of exactly how to do it (and it's not hard). I asked them to remove it but they have so far refused.

I wanted people to know since it makes this a much more serious issue for those affected, which is principally Red Hat and CentOS 7 installs, plus some newer OpenSUSE versions, which isn't heavily used anymore. If people want to warn their communities that this exploit is now very public, that might be warranted.

-- Scott



More information about the announce mailing list