A new security advisory for the product Shibboleth Service Provider (SP) was released on April 26th, 2021 .
It describes a security vulnerability which enables attackers to manipulate certain cookies to make the SP crash (Denial of Service). This error is considered to be medium-critical. All operating systems are affected. We recommend for our customers to upgrade to version 3.2.2. of the SP as soon as possible, as this version contains the patch to fix the aforementioned vulnerability. The new version is available for RPM based Linux distributions as well as Windows. Per experience, the package sources for Ubuntu 20 and Debian 10 (potentially Ubuntu 18 and Debian 9 as well) will soon be provided by SWITCH.
The patches can be found for download in the usual place , or can be installed using the package manager of your operating system. If you commissioned DAASI International with the maintenance of your SP infrastructure, we will take care of the upgrade in a timely manner as part of the support contract. Alternatively, it is also possible to utilise your available helpdesk hours for the upgrade.
If it is not feasible for you to complete the upgrade soon, it is possible to configure an unused Dummy-DataSealer as a workaround (cf.  and the example in the security advisory ). Especially if you are using either Ubuntu or Debian, we recommend to implement this workaround at least until SWITCH provides the updated packages.
DAASI International Support Team: https://shibboleth.net/community/advisories/secadv_20210426.txt
Instructions for the Upgrade
Subscribe to our newsletter
- As NGI Architect DAASI International Presents Concept for Novel Internet Security Techonolgy
- Customised IT Security with Modularity and Open Source
- Peter Gietz as Guest on Podcast for Digital Humanities
- Shibboleth Security Advisory – SP: Denial of Service Due to DataSealer
- Safe Contactless Communication with Open Source: Meet “Jitsi Meet”