git: 928bd4f5b652 - main - security/vuxml: Add security information about opensaml/shibboleth-sp
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Thu, 13 Mar 2025 23:41:08 UTC
The branch main has been updated by girgen:
URL: https://cgit.FreeBSD.org/ports/commit/?id=928bd4f5b6528d1eda5a0a5b498a25bd224ef8d7
commit 928bd4f5b6528d1eda5a0a5b498a25bd224ef8d7
Author: Palle Girgensohn <girgen@FreeBSD.org>
AuthorDate: 2025-03-13 23:02:52 +0000
Commit: Palle Girgensohn <girgen@FreeBSD.org>
CommitDate: 2025-03-13 23:41:04 +0000
security/vuxml: Add security information about opensaml/shibboleth-sp
---
security/vuxml/vuln/2025.xml | 69 ++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 69 insertions(+)
diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml
index 8fb1398fef1b..275e4224a4d2 100644
--- a/security/vuxml/vuln/2025.xml
+++ b/security/vuxml/vuln/2025.xml
@@ -1,3 +1,72 @@
+ <vuln vid="0b43fac4-005d-11f0-a540-6cc21735f730">
+ <topic>shibboleth-sp -- Parameter manipulation allows the forging of signed SAML messages</topic>
+ <affects>
+ <package>
+ <name>opensaml</name>
+ <range><lt>3.3.1</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>The Shibboleth Project reports:</p>
+ <blockquote cite="https://shibboleth.net/community/advisories/secadv_20250313.txt">
+ <p>
+ An updated version of the OpenSAML C++ library is available
+ which corrects a parameter manipulation vulnerability when using
+ SAML bindings that rely on non-XML signatures. The Shibboleth
+ Service Provider is impacted by this issue, and it manifests as
+ a critical security issue in that context.
+ </p>
+ <p>
+ Parameter manipulation allows the forging of signed SAML messages
+ </p>
+ <p>
+ A number of vulnerabilities in the OpenSAML library used by the
+ Shibboleth Service Provider allowed for creative manipulation of
+ parameters combined with reuse of the contents of older requests
+ to fool the library's signature verification of non-XML based
+ signed messages.
+ </p>
+ <p>
+ Most uses of that feature involve very low or
+ low impact use cases without critical security implications;
+ however, there are two scenarios that are much more critical,
+ one affecting the SP and one affecting some implementers who
+ have implemented their own code on top of our OpenSAML library
+ and done so improperly.
+ </p>
+ <p>
+ The SP's support for the HTTP-POST-SimpleSign SAML binding for
+ Single Sign-On responses is its critical vulnerability, and it
+ is enabled by default (regardless of what one's published SAML
+ metadata may advertise).
+ </p>
+ <p>
+ The other critical case involves a mistake that
+ does *not* impact the Shibboleth SP, allowing SSO to occur over
+ the HTTP-Redirect binding contrary to the plain language of the
+ SAML Browser SSO profile. The SP does not support this, but
+ other implementers may have done so.
+ </p>
+ <p>
+ Prior to updating, it is possible to mitigate the POST-SimpleSign
+ vulnerability by editing the protocols.xml configuration file and
+ removing this line:
+ <code><Binding id="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
+ path="/SAML2/POST-SimpleSign" /></code>
+ </p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>https://shibboleth.net/community/advisories/secadv_20250313.txt</url>
+ </references>
+ <dates>
+ <discovery>2025-03-13</discovery>
+ <entry>2025-03-13</entry>
+ </dates>
+ </vuln>
+
<vuln vid="a435609c-ffd5-11ef-b4e4-2cf05da270f3">
<topic>Gitlab -- Vulnerabilities</topic>
<affects>