Upcoming Shibboleth IdP security patch
Paul B. Henson
henson at cpp.edu
Fri May 11 20:59:35 EDT 2018
On Fri, May 11, 2018 at 08:48:37AM +0200, Simon Lundström wrote:
> According to the vulnerability report it only affects Windows?
>
> Does deployers who use something other than Windows need to patch?
There are two vulnerabilities:
* One in Spring, only pertinent to Windows
* One in the idp itself, only pertinent to people running CAS
So, if you neither run the idp under windows, nor use the idp CAS
support, I guess you don't need to worry about this one, at least not
critically.
> On Thu, 2018-05-10 at 20:34:04 +0000, Cantor, Scott wrote:
> >We will be releasing a security patch update for the IdP, V3.3.3,
> >currently planned for next Wednesday, May 16th. The patch includes a
> >Spring Framework bump to pick up a fix for [1] and a security fix for
> >a CAS protocol support issue that we will disclose at that time.
> >
> >The CAS issue is of critical severity. Only deployers using the CAS
> >protocol support are impacted.
> >
> >The Spring issue is potentially high in severity (and is public
> >knowledge) but we don't have any reason to believe most, or possibly
> >any, deployers are affected. But erring on the side of caution
> >because we allow a fair amount of Spring MVC customization, we want
> >to make the fixed version available.
> >
> >-- Scott
--
Paul B. Henson | (909) 979-6361 | http://www.cpp.edu/~henson/
Operating Systems and Network Analyst | henson at cpp.edu
California State Polytechnic University | Pomona CA 91768
More information about the users
mailing list