Skip to content

Conversation

@mend-for-github-com
Copy link

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
com.onelogin:java-saml 2.5.0 -> 2.6.0 age adoption passing confidence

By merging this PR, the issue #17 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 9.1 WS-2018-0629
High High 7.5 CVE-2021-40690

Release Notes

onelogin/java-saml

v2.6.0

Compare Source

  • Check that the certificate of the XML matches the value registered (cert/fingerprint) before validating signature to be able identify such issue.
  • 218 Exposing statuscode and substatuscode through toolkit.
  • 233 When checking IdP Settings, verify with multiple possible IdP certs.
  • 240 Support KeyStore file for SP. Also 243
  • 244 Add StatusCode support for logout response
  • 232 Make Fingerprint check case insensitive
  • Allow duplicated names in AttributeStatement by configuration.
    -253 Expose validation exception in Saml classes
  • Support NameID Encryptation with MultiCert
  • 276 Fix signature validation issue when using fingerprint and sha256 alg
  • 272 Fix format time issues
  • 284 fix nameidNameQualifier typo on logout example
  • 283 Expose a constructor for SamlResponse class which doesn't require HttpRequest
  • 250 Add a stay parameter to Auth processSlo
  • Make ProtocolBinding in the AuthnRequest configurable
  • Metadata constructor now will not set a validUntilTime/cacheDuration if a null parameter is added, if no param provided, it will take constant values.
  • Update dependencies
  • Update the .java-version file to 1.8

  • If you want to rebase/retry this PR, click this checkbox.

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by WhiteSource label May 3, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by WhiteSource

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant