<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Mon, Feb 23, 2015 at 5:24 PM, Tom Scavo <span dir="ltr">&lt;<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">Not sure if I should send this under the radar but here&#39;s a blog post<br>
that claims there&#39;s a vulnerability in some OpenSAML code on the wiki:<br>
<br>
<a href="http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and-the-dangers-of-saml" target="_blank">http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and-the-dangers-of-saml</a></blockquote><div><br></div><div>I believe this hit the users list some time ago.</div><div><br></div><div><a href="http://shibboleth.1660669.n2.nabble.com/web-based-single-sign-on-and-the-dangers-of-saml-xml-td7592366.html">http://shibboleth.1660669.n2.nabble.com/web-based-single-sign-on-and-the-dangers-of-saml-xml-td7592366.html</a></div><div><br></div><div>--Daniel Fisher</div><div> </div></div></div></div>