Red Hat Bugzilla – Bug 1549361
CVE-2018-0489 openSAML: Mishandling of comments in SAML content can lead to bypass of signature verification
Last modified: 2018-10-19 17:47:06 EDT
openSAML does not properly verify comments in SAML content which can allow a remote attacker to modify SAML content without invalidating the cryptographic signature, leading to bypass of primary authentication.
Created opensaml tracking bugs for this issue: Affects: fedora-all [bug 1550480]
The Upstream Advisory is here: https://shibboleth.net/community/advisories/secadv_20180227.txt