xmltooling latest version
Mounika Reddy
mounikareddy2697 at yahoo.com
Fri Sep 15 10:18:39 UTC 2023
Hi,
We are using opensaml-2.x jar in our application for SAML integration. After running a security scan, we found that a vulnerability (CVE-2019-9628) was detected in xmltooling jar, which is a dependent jar of opensaml jar. The Vulnerability Details provided by the tool :
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
I have searched for xmltooling v3.0.4 in maven repository and the sibboleth (http://shibboleth.net/downloads/) websites, but couldn't find the java version of the jar. Could you please confirm if the java version of xmltooling v3.0.4 jar file was released or not.
Thanks,
Mounika
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230915/ff922c64/attachment.htm>
More information about the users
mailing list