Update to 2025-03-13 SP advisory
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 14 17:43:28 UTC 2025
I've updated the advisory issued yesterday [1] to remove the mention of the original workaround I had noted, as it is in fact not effective.
The layering in the design makes it impossible to mitigate at this point in that simple fashion (and even if changed in the future, it wouldn't help existing deployments).
The patch so far as I know still addresses the issue despite the workaround being ineffective, it's not a "new" source of concern.
There is a more aggressive workaround noted in the advisory now, but more likely to cause breakage if done without any planning, though the trade-off may well be advisable for many.
Sorry for the inconvenience.
-- Scott
[1] https://shibboleth.net/community/advisories/secadv_20250313.txt
More information about the announce
mailing list