-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Shibboleth Service Provider Security Advisory [3 September 2025] Updated 9 September 2025. An updated version of the Shibboleth Service Provider is available to correct a SQL injection vulnerability in the ODBC StorageService extension shipped with some distributions of the software. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. This issue was assigned CVE-2025-9943 by the reporter. SQL injection vulnerability in Service Provider ODBC plugin =========================================================== The Shibboleth Service Provider includes a storage API usable for a number of different use cases such as the session cache, replay cache, and relay state management. An ODBC extension plugin is provided with some distributions of the software (notably on Windows). A SQL injection vulnerability was identified in some of the queries issued by the plugin, and this can be creatively exploited through specially crafted inputs to exfiltrate information stored in the database used by the SP. Recommendations =============== Update to V3.5.1 (or later) of the Shibboleth Service Provider, or if you cannot, then migrate off of the ODBC storage plugin/extension. Restarting the shibd process is sufficient to apply the change, as the affected code runs only within that process. Credits ======= SEC Consult Vulnerability Lab Florian Stuhlmann History ======= 2025-09-03 - Initial publication 2025-09-09 - Added CVE assignment URL for this Security Advisory: https://shibboleth.net/community/advisories/secadv_20250903.txt -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3KoVAHvtneaQzZUjN4uEVAIneWIFAmjAXHAACgkQN4uEVAIn eWIDphAAtdPYLhTFWN+Mz95UJtI4N3IANOzssD7Y8eHZosvGKQpsePBNkNDsqmaU g/bj5r9bUj4vv0ruKLZXcMqcARjC8ai9Rq/o4Lvq2uYl3K6pqbaiDR0AajzFOeun Z29Rrnodz87PISTelYYOd/pW3DqHkDfmfLjECLGTe2mljHWdChnLuPxucNoIcbyn Mmj31tMJWtXvjG6l0rWnNJMO8UMmk87X8wTv8hvV1RDzG0bu5zk61/5m9NO3qStU oOCVH1w7I9iQSQWpnGAkHTSjHaFjVIVcIcWWSHdY3kIeI+BiIyn5Z5vSMJFpPDwp WiXDHlQuxKnnhgiqLZBjl6QIdxVikNr4ye/+BS2e5nil+Z3j6+kttzl2PZFO51QV WgN7S+17V2CqkSvgPnzh/R0SBlsULsN1usjlqT8mrGRYOOBIKVP7rWwxeQ9SEnao ckINGaXBmLAGg0oN9Tpqwb82hup1DN29At4hY3zfmcOgwlYlBT4YiFzUBTefSpRu HmhzWjIvb92NcSPt5CYSRRfLMAfeEneYmLLmLMJ0Pg3+Uct2CSR1CkNFyyiihSMK usCYDdyLIXQrTaUq8GJWnaB5kLPiTXM70wVzeevwZFcJCD3tj6cfSreHeI9peNFQ jd1FR4SIogL6hmfY30trvMzztvXV+sWm+eU6P7GPu6EeJgxqmng= =lYap -----END PGP SIGNATURE-----