Shibboleth Service Provider Security Advisory [17 March 2021]
Ullfig, Roberto Alfredo
rullfig at uic.edu
Wed Mar 17 17:05:58 UTC 2021
Where can I find the original post this thread?
---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Wednesday, March 17, 2021 8:07 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: Shibboleth Service Provider Security Advisory [17 March 2021]
On 3/17/21, 8:51 AM, "users on behalf of Ondrej Kosarko" <users-bounces at shibboleth.net on behalf of kosarko at ufal.mff.cuni.cz> wrote:
> I fail to understand if the change in sp v3.2.1 changes the behavior when using redirectErrors in the Errors
> element.
Has nothing to do with that feature except insofar as the exploit effectively could alter what's in the redirect.
However, it stands to reason that anybody relying on error redirection is hard pressed to prevent the same bug in their own code.
Error handling is hard and it is the achilles heel of my "never put identity code inside applications" approach, probably a fatal one. Unfortunately the inverse is unworkable because it means applications are effectively incapable of evolving their identity support (*), and that's not viable either. Don't really have an answer.
-- Scott
(*) Yes, you can change applications. Doesn't happen, not on a campus, at scale.
--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Crullfig%40uic.edu%7Cfb2c2de89d434230171c08d8e94c9a8c%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637515862517797989%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=Q7dgC%2B603e3gnV12OJ1oyWnRm1weY9uif862q6BT96c%3D&reserved=0
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210317/c37e74a1/attachment.htm>
More information about the users
mailing list