Suggestion for XmlTooling 1.4.1: Shibboleth Service Provider Security Advisory [2018-01-12]

Cantor, Scott cantor.2 at osu.edu
Thu Jan 18 09:38:55 EST 2018


 > Can anyone tell me that this vulnerability also exists in xmltooling-1.4.1 jar
> from java end.  If yes should I upgrade this jar..

The advisory is for C++, not Java, and you're already running on EOL Java code that we no longer maintain so you have bigger problems to deal with.

-- Scott




More information about the dev mailing list