IdP patch and Spring CVE
Cantor, Scott
cantor.2 at osu.edu
Fri Aug 15 15:10:31 UTC 2025
Like clockwork, Spring dropped a CVE in the patch they put out just now, immediately after we released V5.1.5.
https://spring.io/security/cve-2025-41242
We do not know of any use of this feature by the IdP, and it also notes that Tomcat and Jetty defaults aren't vulnerable.
However, "path traversal" should strike fear into anybody's heart if you make the mistake of leaving a signing key accessible on disk to a running IdP, so...we're going to issue V5.1.6 immediately to pick up the fix.
Notably, only Spring 6.2 was patched openly, the version we were on prior to 5.1.5 is only being patched in the for-pay version. In other words, this is exactly why we just shipped Spring 6.2 and why [1] was necessary.
So, yeah. And if you aren't current? I hope for your sake we're right that it's not a viable exploit.
The patch will be done by Tuesday latest, probably Monday night I hope.
-- Scott
[1] https://shibboleth.atlassian.net/wiki/spaces/DEV/pages/4570349571
More information about the users
mailing list