SAML2AssertionValidator: Disable access to external entities in XML parsing

Issue #356 resolved
Yavor Vasilev created an issue

Comments (10)

  1. Vladimir Kryukov

    Hi Yavor, will be this fix backported to 8.x? Again the issue is the same - spring-security is using 8.x

  2. Vladimir Kryukov

    @Yavor Vasilev there are a few problems related to this question:

    1. It requires quite a time to figure out is spring-security vulnerable or not
    2. Even if spring-security not providing such feature - it might in the future without additional notice
    3. Overall the vulnerable dependency in the code base is a bad sign

    Not sure how much effort required to bump 8.x with this fix & #357 but I think a lot of people will be grateful to have no critical vulnerabilities in their code base.

  3. Vladimir Kryukov

    Hi @Yavor Vasilev ,

    Thank you, hope you’ll find a time to do that. Could you please reopen this issue to make it visible until it will be fixed also?

    Br.
    Vladimir

  4. Vladimir Dzhuvinov

    @Vladimir Kryukov Just to mention, we are looking for extra maintainers and contributors to this project, even for small tasks and mini projects. If you have a particular interest or topic that you work on let us know.

    For some time I’ve also been contemplating about offering an updates and support subscription by Connect2id with proceeds flowing to maintainers, provided it’s easy to manage and administer. Our paid business comes from selling licenses for the Connect2id server which works goes towards the tip of the SDK, and in that regard backports and maintenance of older branches comes as extra cost.

  5. Log in to comment