Shibboleth Identity Provider + OpenSAML Security Advisory [16 December 2022]

Cantor, Scott cantor.2 at osu.edu
Fri Dec 16 22:28:51 UTC 2022


I have updated this morning's advisory [1] to reflect the fact that testing indicates the suggested workaround of updating the xmlsec jar on older 4.x installs seems to work fine, and made the instructions for that a bit clearer.

Nothing's changed, just clarifying that the possible workaround is in fact sound. Thanks to CINECA for verifying that.

-- Scott

[1] https://shibboleth.net/community/advisories/secadv_20221216.txt




More information about the announce mailing list