-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Shibboleth Identity Provider Security Advisory [26 August 2025] An updated version of the Shibboleth Identity Provider is available to address a cross-site scripting vulnerability in the CAS protocol support when using certain request options that result in a particular response format. XSS vulnerability in one CAS response format ================================================================= An XSS issue was identified in the IdP's handling of CAS responses in certain situations. If exploited, exfiltration of cookies is unlikely due to the default mitigations for that, but cross-site request forgery attacks are very possible against CAS clients that are not themselves hardened against certain kinds of malicious URLs. Recommendations =============== Update to V5.1.6 (or later) of the Identity Provider software. [1] If unable to upgrade, another mitigation requires use of the CAS Service Registry to control use of CAS (rather than the SAML metadata extension specific to our software that many rely on) and the expressions used to validate CAS service URLs would need to be fairly strict and in particular avoid the use of tail-matching regular expression wildcards that would permit essentially any decoration of a URL to be accepted. The SAML metadata alternative exclusively does this sort of open- ended prefix matching and is not designed to prevent further URL content from appearing at the end of a service URL, so its use cannot mitigate against this issue. Credits ======= Discloze, Inc. Dan Malone, California Polytechnic State University [1] https://shibboleth.net/downloads/identity-provider/ URL for this Security Advisory: https://shibboleth.net/community/advisories/secadv_20250826.txt -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3KoVAHvtneaQzZUjN4uEVAIneWIFAmito/4ACgkQN4uEVAIn eWIhixAAmxXv20ZKeEnYJea1A+hhIZ0eLWFUAt+7INi7RdzD8DpoAgmeMC4XjFvA F0rKpszHa+OachTAeCYu1khaw7y46TzsnziyUS6jbO76fJuJ4tveTdW6QO4tTVFA mEFm9MfEzpYql9pBgd0d2sCNjCB/d84smZydg+cYB8OuwCLqA0XUYg5G2rMQAwdF hIrMd5OChPvAuRcUUs7jLYB8c+Fqftw9EgTC0TKDIBVf9izFXugnZwooSyHXYnAO BiePaSvcnYk2jcRtc8YfldcIUuoHbrjTBJGmMRk9XTnNjkCsVF8uJLV3/2QVk7c3 IMFfac4uYX/hRV44JsHD7cYH3GWDhtTSf6b6+yUal4hhpm8ROzCJvBX2TwptzzGE HaTV6+AgVNTmcaN5QvFPtmwUr+Ve2InpVhznp3mQa6tcuA5QAQnBh5MdQwN2HzDl I0USekeSh3slyZCZYAeuf8D28qz6rzwlkhm0nr3uaIUwGoTaGhIIxzXL4mLC3ohN uqeOUS64vF2xCQ6XaOfJa3ha/GnDESpx7TorJBsxYzu9HS+9+0psX842KBNIJ4Ps s+OjXnu7Rc1z82Zf7lNlSj7PNHJEqRmQuWw0OijDMwo01x7vLg36Y9qC52gybHNa LN2kipxdax2wxx6C0jMfCuFJ5SDQovLCInfTAKCcd5CysqPMHbA= =3Tgc -----END PGP SIGNATURE-----