Suggestion for XmlTooling 1.4.1: Shibboleth Service Provider Security Advisory [2018-01-12]

Santu Ghosh mon.snahasish at gmail.com
Thu Jan 18 09:13:42 EST 2018


Hi All

I have an java code base where I used xmltooling 1.4.1 jar to parse SAML
response.

*<groupId>org.opensaml</groupId>*
*<artifactId>xmltooling</artifactId>*
*<version>1.4.1</version>*
*<packaging>jar</packaging>*


Now I have seen the announcement from the shibboleth forum regarding the
security vulnerability of user data during xml processing.

Can anyone tell me that this vulnerability also exists in xmltooling-1.4.1
jar from java end.  If yes should I upgrade this jar..

Please help...

-- 
Snahasish
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20180118/73447735/attachment.html>


More information about the dev mailing list