SecurityAdvisories

This software is not yet released and this is preliminary documentaton subject to significant change. It should not be used in production or to protect important resources at this stage.

SecurityAdvisories

This is the advisory page for Service Provider V4 Hub plugin releases.

For SP Agent plugin advisories, refer to SecurityAdvisories.

This page provides access to the complete history of Security Advisories released for the Shibboleth V4 Service Provider Hub plugins and an "at a glance" table showing you which releases are vulnerable to what kinds of issues. If you're running a particular version, you can use this table to identify the issues that could affect your system and determine how urgent an upgrade is. In addition to the announce mailing list, you can "watch" this page for changes to keep abreast.

You can determine the exact version you're running using the IdP’s plugin management tool and/or its logging, status, and metrics features as with any IdP installation.

If you would like to report an issue you believe is security related, please drop an e-mail to security@shibboleth.net

As always, sites are advised to use the latest stable release of any Shibboleth product. Refer to the ProductVersioning page for information about our support and versioning policies.

This page only covers advisories affecting the V1 Service Provider Hub plugins. Other advisories are not listed here, but you can find the complete set of advisories for all our software in this directory.

Advisory List

Date

Title

Affects

Severity

CVE

Date

Title

Affects

Severity

CVE

 

 

 

 

 

Library Issues

Any unaddressed (and likely irrelevant) issues known to affect third party libraries specific to the hub plugins will be noted here.