Shibboleth Identity Provider + OpenSAML Security Advisory [16 December 2022]
Cantor, Scott
cantor.2 at osu.edu
Fri Dec 16 22:28:51 UTC 2022
I have updated this morning's advisory [1] to reflect the fact that testing indicates the suggested workaround of updating the xmlsec jar on older 4.x installs seems to work fine, and made the instructions for that a bit clearer.
Nothing's changed, just clarifying that the possible workaround is in fact sound. Thanks to CINECA for verifying that.
-- Scott
[1] https://shibboleth.net/community/advisories/secadv_20221216.txt
More information about the announce
mailing list