CAS issues with 5.1.6
Mark Y. Goh
mgoh at cca.edu
Thu Sep 18 21:36:57 UTC 2025
Hi Scott
how do I tell if they are using POST? Configuration on the CAS side is
pretty bare bones - its usually just a URL or sometimes an attribute release
mark
On Thu, Sep 18, 2025 at 1:55 PM Cantor, Scott <cantor.2 at osu.edu> wrote:
> > I assume this behavior is related to CVE-2025-41242 [1] as it
> > does not seem to occur with 5.1.4.
>
> That change only affects tickets relayed with POST, which I don't think is
> common. I would expect literally no difference the traces otherwise.
>
> The risky change is in 5.2 to get off a Spring class building the URLs and
> it hasn't shipped yet.
>
> -- Scott
>
>
>
--
Mark Y. Goh (he/him), Site Reliability Engineer, California College of
the Arts, mgoh at cca.edu
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250918/c2d7229f/attachment.htm>
More information about the users
mailing list