Shibboleth Service Provider Security Advisory [17 March 2021]
Cantor, Scott
cantor.2 at osu.edu
Wed Mar 17 12:12:27 UTC 2021
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Shibboleth Service Provider Security Advisory [17 March 2021]
An updated version of the Service Provider software is available
which fixes a phishing vulnerability.
Template generation allows external parameters to override placeholders
======================================================================
The SP includes a primitive template engine used to render error pages
and various other status or transition pages, and it supports a syntax
for embedding placeholders that are replaced by internally supplied
values or configuration settings.
For reasons that are unclear in the code history, it was extended to
allow replacement via query parameters also, though this is not a
typical need. Because of this feature, it's possible to cause the SP
to display some templates containing values supplied externally by
URL manipulation. Though the values are encoded to prevent script
injection, the content nevertheless appears to come from the server
and so would be interpreted as trustworthy, allowing email addresses,
logos, or support URLs to be manipulated by an attacker.
All platforms are impacted by this issue.
Recommendations
===============
Update to V3.2.1 or later of the Service Provider software, which
is now available.
The update adds a new <Errors> setting to the configuration called
externalParameters, which defaults to false. When false, support for
this "feature" is disabled. In the unlikely event that a valid need
for this exists, the setting can be enabled temporarily to maintain
function until the use case requiring it is addressed in some other
way.
Other Notes
===========
The cpp-sp git commit containing the fix for this issue is
d1dbebfadc1bdb824fea63843c4c38fa69e54379
URL for this Security Advisory:
https://shibboleth.net/community/advisories/secadv_20210317.txt
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE3KoVAHvtneaQzZUjN4uEVAIneWIFAmBR7sAACgkQN4uEVAIn
eWLVdw//VSixULMxvdqzJNP7UASXDvtw7GEfAXvUb8SGJ5cFcElu8QSlzqvUB3v5
XUrLJ4RUbHuOXiaNbfZWvPhAldIH3NoQFidwLQFiiF6afLmmSvof/2Xqnhs2DT/y
n2lj2vRUs/vVDfrpvevnd1NByrnFTVi/BhYxZaF8A6Xc9WZG/i0donrh29NW6h1i
SBoyHtW/AQZxLjSRlj2e70i8e7k0BTllHkxEsMhIzO5PkUWRhvNeLSA4M402M6dm
8DPyt16vRFTvwYmBcRvYSt3qS/4BSDskzqEl7dkRumUHveIg6p8y12oRzQiZypLo
v6EEE/DJ3C6EwxQxoXfYcXWQwPcX1Br0A1JD+twBg10QYMW0foLppvHaj0CX8Xpa
n3/kMsEHyKoFef/U2F3UDOFPUfGEi+GgLssUJljIO5DgkujWg04/+Ue78Qd5pBeF
004Aa3EW/HIBAdoCO7KROtSiyyQHLkoh928soSq0GFpbCoEngsDzeJe273bJLAw2
dfV6wq4jqbbf2PE9xFv5GqxI5bbTId70wVo1LG13oI51YtHcy0AnRhm/Kmp3MeUv
ellYvmvUZAGwQOoapD6Qza47JtYwoNdHGQPbCSEgnU9v87xlys0Gy/ThRit9te+c
M66pBMi3o4i5dIEbyvZOCSOekeFBwRP02yuwh8yV0MbUsOEUffw=
=Kl5A
-----END PGP SIGNATURE-----
More information about the announce
mailing list