Uppdateringen av Shibboleth som kom förra veckan var ett par viktiga säkerhetsuppdatering och det är rekommenderat att uppdatera så snart som möjligt.
Pål
From: announce <announce-bounces@shibboleth.net>
On Behalf Of Scott Cantor via announce
Sent: Wednesday, May 13, 2026 10:09 PM
To: announce@shibboleth.net
Cc: Scott Cantor <scott@restingparrotsoftware.com>
Subject: Shibboleth Identity Provider Security Advisory [13 May 2026]
|
OpenPGP meddelande |
|
Vänta medan meddelandet verifieras... |
|
Shibboleth Identity Provider Security Advisory [13 May 2026]
The Shibboleth Identity Provider has, for some time, included a
A vulnerability in this library, while not deemed critical in
The Jakarta Mail vulnerability was recorded as CVE-2025-7962.
Injection vulnerability in SMTP Library included with IdP
It is typically used in conjunction with a filter to limit
The version of the library shipped with recent versions of the
Because we believe this feature is very little used and because
Recommendations
If making use of the Logback SMTP Appender feature, inject a fixed
See [2] for the project's home page. The self-contained version
Newer versions (V2.1.x) have a separate implementation jar along
Notably, use this feature at your own risk. We as a project do
Credits
[1]
https://logback.qos.ch/manual/appenders.html#SMTPAppender
URL for this Security Advisory:
|