Java Deserialization Vulnerability

Cantor, Scott cantor.2 at osu.edu
Fri Nov 20 17:09:27 EST 2015


On 11/20/15, 4:59 PM, "users on behalf of Quang D Le" <users-bounces at shibboleth.net on behalf of qle3 at lsu.edu> wrote:



>Anybody know if Shibboleth IDP server is vulnerable to the Java
>Deserialization bug?

Not to anybody's knowledge. We don't control what people do in extensions.

>Does anybody know if commons-collections-3.2.1.jar can be removed? If
>so, what are the consequences? (I'm guessing a lot)

No, you can't remove it.

This "bug" is more about programming practices and bad programmers than a normal security bug. Libraries really aren't the issue here.

-- Scott



More information about the users mailing list