Package: opensaml
Version: 3.3.0-2
Severity: grave
Tags: security
X-Debbugs-Cc: team@security.debian.org
As per https://shibboleth.net/community/advisories/secadv_20250313.txt
Parameter manipulation allows the forging of signed SAML messages
=================================================================
RedHat has already a fix available. Not sure if this was coordinated distro-wide but filing a bug just in case (and copying the security team.)
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 482 |
Nodes: | 16 (2 / 14) |
Uptime: | 38:48:53 |
Calls: | 9,566 |
Calls today: | 26 |
Files: | 13,656 |
D/L today: |
2 files (941K bytes) |
Messages: | 6,141,660 |