<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
Hello again,
<div class=""><br class="">
</div>
<div class="">I’ll take your advice and make our installation non-editable by the account running the application. Thanks Scott.</div>
<div class=""><br class="">
</div>
<div class="">I also did a search for ”@InitBinder” and ”dataBinder.setDisallowedFields” as suggested by the waning notice (<a href="https://www.javai.net/post/202203/spring-0day-vulnerability/" class="">https://www.javai.net/post/202203/spring-0day-vulnerability/</a>)
 in the source code of project java-identity-provider (<a href="https://git.shibboleth.net/git/java-identity-provider.git" class="">https://git.shibboleth.net/git/java-identity-provider.git</a>). I did not get any matches, so I suppose we are in the clear for
 now.</div>
<div class=""><br class="">
</div>
<div class="">Regards,</div>
<div class="">Per</div>
<div class=""><br class="">
<div class="">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
<div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<b class="">Per Engström</b><br class="">
Systemutvecklare / Systems Developer<br class="">
 <br class="">
<b class="">SMHI / Swedish Meteorological and Hydrological Institute</b><br class="">
SE - 601 76 NORRKÖPING<br class="">
<a href="http://www.smhi.se" class="">www.smhi.se</a><br class="">
 <br class="">
E-post / Email: per.engstrom@smhi.se<br class="">
Tel / Phone: +46 (0)11 495 83 37<br class="">
Besöksadress / Street address: Folkborgsvägen 17</div>
</div>
</div>
<div><br class="">
<blockquote type="cite" class="">
<div class="">30 mars 2022 kl. 14:02 skrev Cantor, Scott via users <<a href="mailto:users@shibboleth.net" class="">users@shibboleth.net</a>>:</div>
<br class="Apple-interchange-newline">
<div class="">
<div class="">On 3/30/22, 5:12 AM, "users on behalf of Engström Per" <<a href="mailto:users-bounces@shibboleth.net" class="">users-bounces@shibboleth.net</a> on behalf of
<a href="mailto:per.engstrom@smhi.se" class="">per.engstrom@smhi.se</a>> wrote:<br class="">
<br class="">
<blockquote type="cite" class="">Does this need to be handled?<br class="">
</blockquote>
<br class="">
An actual security advisory issued by the Spring Project and a remediation, fix, or workaround would, yes. Until that happens, there's nothing we can do.<br class="">
<br class="">
We can't hold 4.2 forever but we'll wait an appropriate amount of time to ship until we know what's going on. If warranted, we'll consider a patch for 4.1.<br class="">
<br class="">
I will say that, as with some of the previous logging issues, the obvious thing everyone should do is fix any systems that are running their servlet container under accounts with write access to the IdP's code and configuration. Doing that is the quickest way
 to open oneself up to an RCE (ok, second quickest, but "don't run anything on the web" unfortunately isn't an option here).<br class="">
<br class="">
-- Scott<br class="">
<br class="">
<br class="">
-- <br class="">
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" class="">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">
users-unsubscribe@shibboleth.net</a><br class="">
</div>
</div>
</blockquote>
</div>
<br class="">
</div>
</body>
</html>