OIDC OP plugin v3.0.3 now available

Martin Haase Martin.Haase at DAASI.de
Wed Jan 5 11:34:06 UTC 2022

Dear Henri, dear team,

can anybody tell if the pre-Plugin (2020) OIDC extension, i.e. v2.0.0
from https://github.com/CSCfi/shibboleth-idp-oidc-extension, suffers
from that security issue likewise?



Am 03.01.22 um 16:14 schrieb Henri Mikkonen:
> The Shibboleth Project has released V3.0.3 of the OIDC OP plugin (see
> release notes at [1])
> The primary reason for the patch is a fix for a security issue related
> to the validation of incoming JSON Web Tokens (JWTs). There will be a
> security advisory published right after this announcement with
> additional details to finalize the release.
> -- Henri Mikkonen, on behalf of the team
> [1]
> https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/2776760321/OPReleaseNotes
> -- 
> To unsubscribe from this list send an email to
> announce-unsubscribe at shibboleth.net

Dr. Martin Haase, Solutions Engineer

DAASI International
Europaplatz 3                   
D-72072 Tübingen                

phone: +49 7071 407109-0
fax:   +49 7071 407109-9  
email: martin.haase at daasi.de
web:   www.daasi.de

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz

More information about the users mailing list