Significant OpenSAML advisories/patches

Jason Howe jhowe at cs.washington.edu
Thu Mar 13 17:47:26 UTC 2025


On 3/13/25 10:41 AM, Cantor, Scott via users wrote:
>> Someone pointed out to me that simplesamlphp just release
>> a new version to address a security vulnerability that has
>> some of the keywords as the opensaml issue. If that turns
>> out to be close enough to enable an attacker to exploit the
>> opensaml issue, might justify speeding up release.
> If we need to it's ready, I just wanted more testing done to avoid regressions and I don't have any ready way to do that, I don't run SPs really at all anymore.
>
> That GitHub issue should not have been made public in that form and it's irresponsible of them to have done so.
>
> For the record, the SP issue that matters does not involve HTTP-Redirect  because no SP should ever accept SSO responses over that binding, it is a MUST NOT in the standard to do so. Forging logout messages isn't something we see as critical.
>
> If you see a commercial SP allowing that, they quite likely have a serous, serious issue to fix. That's all I can say on that.
>
> -- Scott
>
I've installed the pre-release RPMs on a test SP, no issues detected so 
far with our very vanilla use case with HTTP-POST bindings.

--Jason



More information about the users mailing list