Java Deserialization Vulnerability
Quang D Le
qle3 at lsu.edu
Fri Nov 20 16:59:56 EST 2015
All,
Anybody know if Shibboleth IDP server is vulnerable to the Java
Deserialization bug?
http://www.darkreading.com/informationweek-home/why-the-java-deserialization-bug-is-a-big-deal/d/d-id/1323237
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/
I followed the FoxGlove Security article, and found that Shibboleth IDP
server does have the vulnerable, commons-collections-3.2.1.jar, in
/opt/shibboleth-idp/lib/commons-collections-3.2.1.jar:
grep -R InvokerTransformer .
Binary file ./lib/commons-collections-3.2.1.jar matches
Does anybody know if commons-collections-3.2.1.jar can be removed? If
so, what are the consequences? (I'm guessing a lot)
Any information is greatly appreciated. Thank you.
--
Quang D Le
ITS - Security
225-578-4932
qle3 at lsu.edu
More information about the users
mailing list