<div dir="ltr"><div>Hi Scott </div><div>how do I tell if they are using POST? Configuration on the CAS side is pretty bare bones - its usually just a URL or sometimes an attribute release</div><br><div>mark</div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Thu, Sep 18, 2025 at 1:55 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> I assume this behavior is related to CVE-2025-41242 [1] as it<br>
> does not seem to occur with 5.1.4. <br>
<br>
That change only affects tickets relayed with POST, which I don't think is common. I would expect literally no difference the traces otherwise.<br>
<br>
The risky change is in 5.2 to get off a Spring class building the URLs and it hasn't shipped yet.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div><div><br clear="all"></div><br><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature"><div dir="ltr"><pre cols="72"><font face="arial, helvetica, sans-serif">Mark Y. Goh (he/him), Site Reliability Engineer, California College of the Arts, <a href="mailto:mgoh@cca.edu" target="_blank">mgoh@cca.edu</a></font><span></span><br></pre></div></div>