Suggestion for XmlTooling 1.4.1: Shibboleth Service Provider Security Advisory [2018-01-12]

Santu Ghosh mon.snahasish at gmail.com
Thu Jan 18 10:45:18 EST 2018


Thank you all for your response.

Can you please guide me to the next step to overcome this and make this
code up-to-date.

Is there any document or link on how to upgrade this ?

Please help..



On Thu, Jan 18, 2018 at 8:11 PM, Rod Widdowson <rdw at steadingsoftware.com>
wrote:

> > <groupId>org.opensaml</groupId>
> > <artifactId>xmltooling</artifactId>
> > <version>1.4.1</version>
> > <packaging>jar</packaging>
>
> Well that jar is over 2 years old on an unmaintained (for more than 2
> years) development branch and is therefore subject to multiple SecAdvs.
> Several probably significantly more serious than this one
>
> But one of them won't be the one you quote since it is for C++ and you are
> speaking Java.
>
> > Please help...
>
> Update to the latest OpenSAML.  But bear in mind that XMLTooling (C++) and
> OpenSAML (C++, Java) is maintained uniquely in support of Shibboleth.
>
> R
>
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
>



-- 
Snahasish
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20180118/792d0fa8/attachment.html>


More information about the dev mailing list