Upcoming Shibboleth IdP security patch

Simon Lundström simlu at su.se
Fri May 11 02:48:37 EDT 2018


According to the vulnerability report it only affects Windows?

Does deployers who use something other than Windows need to patch?

BR,
- Simon

On Thu, 2018-05-10 at 20:34:04 +0000, Cantor, Scott wrote:
>We will be releasing a security patch update for the IdP, V3.3.3, currently planned for next Wednesday, May 16th. The patch includes a Spring Framework bump to pick up a fix for [1] and a security fix for a CAS protocol support issue that we will disclose at that time.
>
>The CAS issue is of critical severity. Only deployers using the CAS protocol support are impacted.
>
>The Spring issue is potentially high in severity (and is public knowledge) but we don't have any reason to believe most, or possibly any, deployers are affected. But erring on the side of caution because we allow a fair amount of Spring MVC customization, we want to make the fixed version available.
>
>-- Scott
>
>[1] https://pivotal.io/security/cve-2018-1271
>--
>To unsubscribe from this list send an email to announce-unsubscribe at shibboleth.net


More information about the users mailing list