CVE-2011-1411: OpenSAML library vulnerable to XML Signature wrapping attacks
Brent Putman
putmanb at georgetown.edu
Wed Jan 9 17:43:29 EST 2013
On 1/9/13 10:35 AM, Cantor, Scott wrote:
> On 1/9/13 10:25 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>> The question seems to be about the SVN revision this was fixed it.
>> There's no jira issue assigned to the 2.5.1 release, but it seems to
>> be around r1537 to r1539.
> The code is spread across different projects, and I don't know if the
> fixes were only to that jar but the tag says 1544.
I believe the only relevant changes were in java-opensaml2, and the the
exact revisions were: 1537, 1538, 1549
1549 is just the unit tests, which were checked in later so as not to
server as a cookbook for exploiting the vulnerability.
The Jira issue is JOST-161, and this info is listed there, but it
appears to be non-public, since it's flagged as a vulnerability.
--Brent
More information about the dev
mailing list