Changelog
xmltooling (3.2.4-1) unstable; urgency=medium
* [f89bdd8] New upstream release: 3.2.4
SECURITY: corrects a server-side request forgery (SSRF) vulnerability.
From https://shibboleth.net/community/advisories/secadv_20230612.txt:
# Parsing of KeyInfo elements can cause remote resource access
Including certain legal but "malicious in intent" content in the
KeyInfo element defined by the XML Signature standard will result
in attempts by the SP's shibd process to dereference untrusted URLs.
While the content of the URL must be supplied within the message
and does not include any SP internal state or dynamic content,
there is at minimum a risk of denial of service, and the attack
could be combined with others to create more serious vulnerabilities
in the future. (Closes: #1037948)
* [79533dd] Delete upstreamed patch
* [6ae406d] Remove Etienne Dysli Metref from Uploaders.
Thanks for your work, Etienne, and best wishes for your future
endeavors!
-- Ferenc Wágner <email address hidden> Wed, 14 Jun 2023 22:04:20 +0200