IdP patch and Spring CVE

Cantor, Scott cantor.2 at osu.edu
Tue Aug 19 17:50:39 UTC 2025


As it happens, on top of the Spring issue, a security report came in.

That fix is being included in the 5.1.6 release, but will delay it a bit, hopefully not into next week but that's possible.

I provided a little more detail about that to the member alert list but I won't say more here other than it's a significant issue and it only impacts use of CAS.

-- Scott




More information about the users mailing list