Suggestion for XmlTooling 1.4.1: Shibboleth Service Provider Security Advisory [2018-01-12]
Santu Ghosh
mon.snahasish at gmail.com
Thu Jan 18 09:13:42 EST 2018
Hi All
I have an java code base where I used xmltooling 1.4.1 jar to parse SAML
response.
*<groupId>org.opensaml</groupId>*
*<artifactId>xmltooling</artifactId>*
*<version>1.4.1</version>*
*<packaging>jar</packaging>*
Now I have seen the announcement from the shibboleth forum regarding the
security vulnerability of user data during xml processing.
Can anyone tell me that this vulnerability also exists in xmltooling-1.4.1
jar from java end. If yes should I upgrade this jar..
Please help...
--
Snahasish
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20180118/73447735/attachment.html>
More information about the dev
mailing list