Shibboleth Identity Provider Security Advisory [4 October 2017]

Cantor, Scott cantor.2 at osu.edu
Wed Nov 22 15:59:52 EST 2017


On 11/21/17, 10:42 PM, "users on behalf of Baron Fujimoto" <users-bounces at shibboleth.net on behalf of baron at hawaii.edu> wrote:

> Given that we are using V3.2.1, does that mean our mitigation option,
> short of upgrading our IdP, is to replace the version of ldaptive inside
> the deployed warfile with the latest ldaptive version?

Yes, but the solution is to patch your system. That should not even be a question, it's not optional.

-- Scott




More information about the users mailing list