Page tree
Skip to end of metadata
Go to start of metadata

You can follow this space for news about the project and software releases, though it is strongly advised that you subscribe to the announce mailing list instead. There may be lag in important information appearing here.

The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20190311.txt regarding a denial of service vulnerability. Updated packages are available that correct the issue.
An SP patch release has been made available to address a security issue https://shibboleth.net/community/advisories/secadv_20190311.txt and address a few small bugs.
The Shibboleth Project has released version 3.4.3 https://shibboleth.net/downloads/identity-provider/3.4.3/ of the Identity Provider software. This is a patch upgrade to fix a pair of regressions. See the announcement https://shibboleth.net/pipermail/announce/2019-January/000194.html for further details.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20181219.txt https://shibboleth.net/community/advisories/secadv_20181219.txt that involves a vulnerability to information disclosure via the CAS protocol.
The Shibboleth Project has released version 3. https://shibboleth.net/downloads/identity-provider/3.3.3/4.2 of the Identity Provider software, a patch upgrade. See the announcement https://shibboleth.net/pipermail/announce/2018-December/000190.html for further details. This release is in conjunction with a security advisory https://shibboleth.net/community/advisories/secadv_20181219.txt.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20181219a.txt regarding a denial of service vulnerability. Updated packages are available that correct the issue.
A third SP patch release has been made available to address a security issue https://shibboleth.net/community/advisories/secadv_20181219a.txt and make other library updates available to Windows deployers. Additional patch releases may be warranted as more adoption and testing occurs so please stay tuned to the announce https://shibboleth.net/mailman/listinfo/announce list.
The Shibboleth Project has released a minor feature upgrade, V3.4.0, of its Identity Provider software. See the announcement https://shibboleth.net/pipermail/announce/2018-October/000187.html for further details.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20180803.txt that highlights a bug corrected in a third-party library that addresses a denial of service vulnerability in the SP. Updated packages are available that correct the issue. Note that this is the first issue that impacts SP V2 that cannot efficiently be addressed by the project,…
A second SP patch release has been made available to fix more bugs identified by early adopters and make other library updates available to Windows deployers. Additional patch releases may be warranted as more adoption and testing occurs so please stay tuned to the announce https://shibboleth.net/mailman/listinfo/announce list.
An SP patch release has been quickly made available to fix some major problems identified by early adopters. Additional patch releases may be warranted as more adoption and testing occurs so please stay tuned to the announce https://shibboleth.net/mailman/listinfo/announce list.
The Shibboleth Project has released https://shibboleth.net/pipermail/announce/2018-July/000183.html the first major upgrade to the Service Provider software in a number of years. It is a backward-compatible release designed to be a direct upgrade for existing deployments. This release provides long-awaited support for OpenSSL 1.1 to facilitate availability in newer Linux distributions.
The Shibboleth Project has announced http://shibboleth.net/pipermail/announce/2018-May/000181.html the release of V3.3.3 https://shibboleth.net/downloads/identity-provider/3.3.3/ of the Identity Provider software, a patch upgrade. This release is in conjunction with a security advisory https://shibboleth.net/community/advisories/secadv_20180516.txt.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20180516.txt that involves a vulnerability to information disclosure via the CAS protocol. A patch release is now available https://shibboleth.net/downloads/identity-provider/3.3.3/ that corrects the issue.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20180227.txt that involves the XML processing performed by the Service Provider. An xmltooling patch update, V1.6.4, is available that corrects the issue on all platforms.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20180112.txt that involves the XML processing performed by the Service Provider on a subset of platforms limited to an older version of the Xerces library. An xmltooling patch update, V1.6.3, is available that corrects the issue on platforms not already protected by an updated XML parser.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20171115.txt that involves the Dynamic MetadataProvider feature in the Service Provider. A patch update, V2.6.1, is available http://shibboleth.net/pipermail/announce/2017-November/000168.html that corrects the issue.
 The Shibboleth Project has released V2.6.1 of the Service Provider software, to correct a security issue https://shibboleth.net/community/advisories/secadv_20171115.txt. Release notes for this release and previous versions are here https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPReleaseNotes.
The Shibboleth Project has announced http://shibboleth.net/pipermail/announce/2017-October/000166.html the release of V3.3.2 https://shibboleth.net/downloads/identity-provider/3.3.2/ of the Identity Provider software, a patch upgrade. This release is in conjunction with a security advisory https://shibboleth.net/community/advisories/secadv_20171004.txt.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20171004.txt that involves a potential MITM attack against LDAP data connections using "ldaps". A patch release is now available https://shibboleth.net/downloads/identity-provider/3.3.2/ that corrects the issue and takes steps to prevent its recurrence.


  • No labels