CVE-2011-1411: OpenSAML library vulnerable to XML Signature wrapping attacks

Cantor, Scott cantor.2 at osu.edu
Wed Jan 9 10:35:23 EST 2013


On 1/9/13 10:25 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>
>The question seems to be about the SVN revision this was fixed it.
>There's no jira issue assigned to the 2.5.1 release, but it seems to
>be around r1537 to r1539.

The code is spread across different projects, and I don't know if the
fixes were only to that jar but the tag says 1544.

-- Scott




More information about the dev mailing list