Does Shibboleth use Apache "Struts2"?

David Gersic dgersic at niu.edu
Mon Jul 29 15:06:28 EDT 2013


This is very sketchy, and I'll apologize in advance for that. Our security department here has heard (source unknown) that some universities (unspecified) have been hit by a security vulnerability in something called Struts2 (http://struts.apache.org/development/2.x/).

I'm told that there is at least one university (unknown which one) that thinks (?) that maybe Shibboleth (doesn't specify SP, IdP, version(s), etc.) may (?) be using Struts2. So, now our security department are asking me if we're affected by this supposed maybe vulnerability in something I've never heard of.

<sigh/>

I'm running shibboleth-identityprovider-2.3.5 here. We're not running any SP here. Does the IdP have any use of this "Struts2" thing? I'm pretty sure it doesn't, but I have to ask.

Security Advisories site for Shibboleth (https://wiki.shibboleth.net/confluence/display/SHIB2/SecurityAdvisories) doesn't have anything on this vulnerability, but that's not surprising, given the information available to me at this time.





More information about the users mailing list