Uploaded image for project: 'mod-login-saml'
  1. mod-login-saml
  2. MODLOGSAML-130

Pac4j 5.2.1, RMB 33.2.4, vertx-pac4j 6.0.0 fixing unsecure token (CVE-2021-44878)

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • TBD
    • Resolution: Done
    • None
    • 2.4.0
    • CP: sprint 131
    • 1
    • Core: Platform

    Description

      Pac4j v5.1 and earlier allows (by default) clients to accept and successfully validate ID Tokens with "none" algorithm. This is insecure because it disables signature validation:

      Update Pac4j from 5.1.4 to 5.2.1.

      Also update RMB 33.2.3 to 33.2.4 (this bumps log4j from 2.17.0 to 2.17.1).

      And update vertx-pac4j from 6.0.0-FOLIO.1 to 6.0.0.

      TestRail: Results

        Attachments

          Activity

            People

              julianladisch Julian Ladisch
              julianladisch Julian Ladisch
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                TestRail: Runs

                  TestRail: Cases