Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check SubjectConfirmation handling #103

Closed
AndersAbel opened this issue Aug 27, 2014 · 2 comments
Closed

Check SubjectConfirmation handling #103

AndersAbel opened this issue Aug 27, 2014 · 2 comments

Comments

@AndersAbel
Copy link
Member

AuthServices currently behaves as if all assertions have the bearer SubjectConfirmation method. Check that assertions with other subject confirmation methods are not accepted.

@AndersAbel AndersAbel added the bug label Jun 16, 2016
AndersAbel added a commit that referenced this issue Apr 21, 2020
AndersAbel added a commit that referenced this issue Apr 21, 2020
@AndersAbel AndersAbel modified the milestones: v1.0.2, v2.7.0 Apr 21, 2020
@NicoleG25
Copy link

Hi @AndersAbel Does this refer to CVE-2020-5268 ?
Thanks in advance !

@AndersAbel
Copy link
Member Author

@NicoleG25 Yes, I should have linked to the CVE from here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants