Shibboleth Service Provider Security Advisory [17 March 2021]

Cantor, Scott cantor.2 at osu.edu
Wed Mar 17 13:07:38 UTC 2021


On 3/17/21, 8:51 AM, "users on behalf of Ondrej Kosarko" <users-bounces at shibboleth.net on behalf of kosarko at ufal.mff.cuni.cz> wrote:

>    I fail to understand if the change in sp v3.2.1 changes the behavior when using redirectErrors in the Errors
> element.

Has nothing to do with that feature except insofar as the exploit effectively could alter what's in the redirect.

However, it stands to reason that anybody relying on error redirection is hard pressed to prevent the same bug in their own code.

Error handling is hard and it is the achilles heel of my "never put identity code inside applications" approach, probably a fatal one. Unfortunately the inverse is unworkable because it means applications are effectively incapable of evolving their identity support (*), and that's not viable either. Don't really have an answer.

-- Scott

(*) Yes, you can change applications. Doesn't happen, not on a campus, at scale.



More information about the users mailing list