cryptacular dependency
Andrew Vinall
andrew.vinall at forgerock.com
Mon Mar 2 07:16:21 EST 2020
Hi
OpenSAML has a dependency on cryptacular:1.1.3. However, there is a
security vulnerability with a CVSS score of 7.3 on cryptacular:1.1.3
https://nvd.nist.gov/vuln/detail/CVE-2020-7226.
This problem has a fix and has been addressed in
* cryptacular:1.2.4 (https://github.com/vt-middleware/cryptacular/issues/52)
* cryptacular:1.1.4
(https://github.com/vt-middleware/cryptacular/pull/56 &
https://github.com/vt-middleware/cryptacular/compare/v1.1.3...v1.1.4)
I understand Version 4 of Shibboleth will include this update.
However, could the 3.x branch be updated to include the backported fix
in cryptacular 1.1.4? Note it is built with JDK7 like its previous
version.
Thanks
Andrew
--
Andrew Vinall
Software Test Engineer | ForgeRock
t (+44) 7545194526 | e andrew.vinall at forgerock.com
web www.forgerock.com
More information about the dev
mailing list