-
Notifications
You must be signed in to change notification settings - Fork 4
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Create 2024-11-25-upcoming-security-release.md
- Loading branch information
Showing
1 changed file
with
17 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
Hi! | ||
|
||
We've been made aware of a security issue in one of the dependencies of SimpleSAMLphp, | ||
The developers have evaluated the impact for SimpleSAMLphp, which we found to be high. | ||
If you're using older versions or forks, please make sure you can build and release patched versions quickly. | ||
|
||
Timeline will be as follows: | ||
|
||
- Patch release on Sunday Dec 1st (as late as possible CET zone). | ||
- New releases for OpenConext and SimpleSAMLphp the next day on Dec 2nd as early as possible. | ||
- Publication of the security advisory with disclosure on the vulnerability on Sunday 8th. | ||
|
||
We understand this message will raise questions about the impact and the scope of the vulnerability, but please understand that we cannot answer any questions as long as this vulnerability is under embargo. | ||
|
||
Kind regards, | ||
|
||
The developer-team |