IdP patch and Spring CVE

Cantor, Scott cantor.2 at osu.edu
Fri Aug 15 15:10:31 UTC 2025


Like clockwork, Spring dropped a CVE in the patch they put out just now, immediately after we released V5.1.5.

https://spring.io/security/cve-2025-41242

We do not know of any use of this feature by the IdP, and it also notes that Tomcat and Jetty defaults aren't vulnerable.

However, "path traversal" should strike fear into anybody's heart if you make the mistake of leaving a signing key accessible on disk to a running IdP, so...we're going to issue V5.1.6 immediately to pick up the fix.

Notably, only Spring 6.2 was patched openly, the version we were on prior to 5.1.5 is only being patched in the for-pay version. In other words, this is exactly why we just shipped Spring 6.2 and why [1] was necessary.

So, yeah. And if you aren't current? I hope for your sake we're right that it's not a viable exploit.

The patch will be done by Tuesday latest, probably Monday night I hope.

-- Scott 

[1] https://shibboleth.atlassian.net/wiki/spaces/DEV/pages/4570349571



More information about the users mailing list