CVE-2011-1411: OpenSAML library vulnerable to XML Signature wrapping attacks

gprestia gregoriogianluca.prestia at amadeus.com
Mon Jan 14 08:44:33 EST 2013


Hello again,
I downloaded version 2.5.3 of opensaml and I'm attempting to build it with
maven.

The build fails because the maven repository URLs are unreachable and this
prevents downloading the parent POM and the dependencies.

Precisely, the following URLs return a 404, even if they appear to be public
repositories and are declared in the POM:
- https://shibboleth.net/nexus/content/groups/public
- https://shibboleth.net/nexus/content/repositories/snapshots

* I must be just another PEBKAC, but normally I'm used to see maven projects
work out-of-the-box...

Thanks in advance
GP



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/CVE-2011-1411-OpenSAML-library-vulnerable-to-XML-Signature-wrapping-attacks-tp6618773p7584020.html
Sent from the Shibboleth - Developers mailing list archive at Nabble.com.


More information about the dev mailing list