-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Shibboleth Service Provider Security Advisory [13 March 2025] OpenSAML-C++ Security Advisory [13 March 2025] Last updated on [18 March 2025] An updated version of the OpenSAML C++ library is available which corrects a parameter manipulation vulnerability when using SAML bindings that rely on non-XML signatures. The Shibboleth Service Provider is impacted by this issue, and it manifests as a critical security issue in that context. Parameter manipulation allows the forging of signed SAML messages ================================================================= A number of vulnerabilities in the OpenSAML library used by the Shibboleth Service Provider allowed for creative manipulation of parameters combined with reuse of the contents of older requests to fool the library's signature verification of non-XML based signed messages. Most uses of that feature involve very low or low impact use cases without critical security implications; however, there are two scenarios that are much more critical, one affecting the SP and one affecting some implementers who have implemented their own code on top of our OpenSAML library and done so improperly. The SP's support for the HTTP-POST-SimpleSign SAML binding for Single Sign-On responses is its critical vulnerability, and it is enabled by default (regardless of what one's published SAML metadata may advertise). The other critical case involves a mistake that does *not* impact the Shibboleth SP, allowing SSO to occur over the HTTP-Redirect binding contrary to the plain language of the SAML Browser SSO profile. The SP does not support this, but other implementers may have done so. Recommendations =============== Update to V3.3.1 (or later) of the OpenSAML library package. On non-Windows platforms this is sufficient to address the issue with a subsequent restart of the SP's "shibd" daemon to pick up the change. On Windows, the Service Provider V3.5.0.1 (or later) installer contains the updated OpenSAML DLL and must be applied to obtain the fix. V3.5.0.2 corrects a mistake in one log line that failed to report the proper library version but is otherwise the same code as V3.5.0.1. The "shibd" log file will log the library versions n use and the OpenSAML version should be at least 3.3.1 to indicate the fix is applied. Contrary to the initial publication of this advisory, there is no workaround within the SP configuration other than to remove the "SimpleSigning" security policy rule from the security-policy.xml file entirely. That will also prevent support of legitimate signed requests or responses via the HTTP-Redirect binding, which is generally used only for logout messages within the SP itself. Maintaining support for logout while applying the mitigation to the SP is possible by removing the HTTP-Redirect binding from an SP's metadata so that IdP(s) will select the HTTP-POST binding (using XML-based signatures) in its place. Credits ======= Thanks to Alexander Tan of SecureSAML for discovering and reporting this vulnerability, and reviewing the changes. History ======= 2025-03-14 - remove the mention of original ineffective workaround. 2025-03-17 - clarify the end of the mitigation section and a mistake in one of the log lines mentioned. 2025-03-18 - remove log line mention after uploading fixed installer URL for this Security Advisory: https://shibboleth.net/community/advisories/secadv_20250313.txt -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3KoVAHvtneaQzZUjN4uEVAIneWIFAmfZipsACgkQN4uEVAIn eWLxzBAAll5GK4WLY3A82iqZmHyYk9N+45FZnnV78sIaOW0QT3rsH4hB+7PsxzDC jWJ3b6FZI0yLywn3CZfN4pg94ubsKhwwbwnYPI1D0K4pijN95YzZKauPsKDSDG3m uCk0OKdds+NvO/A4Z1W2d3FN5ymD12u5MebynGTyxVlgr5B/s9xW+eZi7m5filMe WQJrbXJ6qjArA9SdN0ETz9BdT4UEgN3OqER8VBbQAs4E7BBjnmN8yWB4cfdbkvNs 5S4ZBqdTKHKwPHTDmV7pGtm7KJnSgm9FnDgSkvLjQxlFlQT8Sq8Z+3sNGZAqi10C 6bvam4zMFfKPqlWu/1p44Dyy4DfyvFbRRsl8LHTdua1lhrcFvPphg8cT0/BB7+Xi FN3S0rUhEdOI0stiZnQQlz7cimskUTX05UoeHesqU3/p5LdMznqZCi0OZLP0D9ta zyMxgrFbeDzDwB1JV+Nx8zP+Od8o+x/l8NeHdGbGLWGBKWOtQAtCBvcxX2xSm9tt CxLG0dvLsyj0IGt0HrFr0lFsPXzofer9MDMF5qgUHlNXbe1oL2orV6YQwcs/QmBk oXMNkkrqoitq2PMSJUkJYOTeb2LyVFRdRxlxQD5zq1wgK5Pf2vnOkR9VIpU2YitH wFDEGviAdxwYjLOzXAi6Jue4CHfdlAxwdL5TwHYG/S5vEs9HxII= =WxZx -----END PGP SIGNATURE-----