Java Deserialization Vulnerability
Cantor, Scott
cantor.2 at osu.edu
Fri Nov 20 17:09:27 EST 2015
On 11/20/15, 4:59 PM, "users on behalf of Quang D Le" <users-bounces at shibboleth.net on behalf of qle3 at lsu.edu> wrote:
>Anybody know if Shibboleth IDP server is vulnerable to the Java
>Deserialization bug?
Not to anybody's knowledge. We don't control what people do in extensions.
>Does anybody know if commons-collections-3.2.1.jar can be removed? If
>so, what are the consequences? (I'm guessing a lot)
No, you can't remove it.
This "bug" is more about programming practices and bad programmers than a normal security bug. Libraries really aren't the issue here.
-- Scott
More information about the users
mailing list