Upcoming Shibboleth IdP security patch

Paul B. Henson henson at cpp.edu
Fri May 11 20:59:35 EDT 2018


On Fri, May 11, 2018 at 08:48:37AM +0200, Simon Lundström wrote:
> According to the vulnerability report it only affects Windows?
> 
> Does deployers who use something other than Windows need to patch?

There are two vulnerabilities:

* One in Spring, only pertinent to Windows
* One in the idp itself, only pertinent to people running CAS

So, if you neither run the idp under windows, nor use the idp CAS
support, I guess you don't need to worry about this one, at least not
critically.

> On Thu, 2018-05-10 at 20:34:04 +0000, Cantor, Scott wrote:
> >We will be releasing a security patch update for the IdP, V3.3.3,
> >currently planned for next Wednesday, May 16th. The patch includes a
> >Spring Framework bump to pick up a fix for [1] and a security fix for
> >a CAS protocol support issue that we will disclose at that time.
> >
> >The CAS issue is of critical severity. Only deployers using the CAS
> >protocol support are impacted.
> >
> >The Spring issue is potentially high in severity (and is public
> >knowledge) but we don't have any reason to believe most, or possibly
> >any, deployers are affected. But erring on the side of caution
> >because we allow a fair amount of Spring MVC customization, we want
> >to make the fixed version available.
> >
> >-- Scott

-- 
Paul B. Henson  |  (909) 979-6361  |  http://www.cpp.edu/~henson/
Operating Systems and Network Analyst  |  henson at cpp.edu
California State Polytechnic University  |  Pomona CA 91768


More information about the users mailing list