Shibboleth Identity Provider Security Advisory [27 October 2016]
Cantor, Scott
cantor.2 at osu.edu
Thu Oct 27 17:11:21 EDT 2016
Apologies for this going out at 5pm Eastern, but a) it's a bad one, b) it was publically disclosed inadvertently, c) it's easy to mitigate for the majority of sites, and d) it's not particularly exploitable in any deliberate way just by having knowledge of it so not knowing about it until the morning isn't going to have put anybody at any greater risk. Soonest possible wider dissemination seemed best.
-- Scott
More information about the users
mailing list