Significant OpenSAML advisories/patches
Cantor, Scott
cantor.2 at osu.edu
Thu Mar 13 17:41:52 UTC 2025
> Someone pointed out to me that simplesamlphp just release
> a new version to address a security vulnerability that has
> some of the keywords as the opensaml issue. If that turns
> out to be close enough to enable an attacker to exploit the
> opensaml issue, might justify speeding up release.
If we need to it's ready, I just wanted more testing done to avoid regressions and I don't have any ready way to do that, I don't run SPs really at all anymore.
That GitHub issue should not have been made public in that form and it's irresponsible of them to have done so.
For the record, the SP issue that matters does not involve HTTP-Redirect because no SP should ever accept SSO responses over that binding, it is a MUST NOT in the standard to do so. Forging logout messages isn't something we see as critical.
If you see a commercial SP allowing that, they quite likely have a serous, serious issue to fix. That's all I can say on that.
-- Scott
More information about the users
mailing list