USN-7364-1: OpenSAML vulnerability
21 March 2025
OpenSAML and OpenSAML2 could have their authentication systems bypassed.
Releases
- Ubuntu 25.04
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 ESM
- Ubuntu 16.04 ESM
Packages
- opensaml - Security Assertion Markup Language library (development)
- opensaml2 - Security Assertion Markup Language library (development)
Details
Alexander Tan discovered that the OpenSAML C++ library was susceptible to
forging of signed SAML messages. An attacker could possibly use this issue
to gain unauthorized access to a system and manipulate sensitive
information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 25.04
-
libsaml-dev
-
3.3.0-2ubuntu1
-
libsaml13
-
3.3.0-2ubuntu1
-
opensaml-schemas
-
3.3.0-2ubuntu1
-
opensaml-tools
-
3.3.0-2ubuntu1
Ubuntu 24.10
-
libsaml-dev
-
3.2.1-4.1ubuntu0.24.10.1
-
libsaml12t64
-
3.2.1-4.1ubuntu0.24.10.1
-
opensaml-schemas
-
3.2.1-4.1ubuntu0.24.10.1
-
opensaml-tools
-
3.2.1-4.1ubuntu0.24.10.1
Ubuntu 24.04
-
libsaml-dev
-
3.2.1-4.1ubuntu0.24.04.1
-
libsaml12t64
-
3.2.1-4.1ubuntu0.24.04.1
-
opensaml-schemas
-
3.2.1-4.1ubuntu0.24.04.1
-
opensaml-tools
-
3.2.1-4.1ubuntu0.24.04.1
Ubuntu 22.04
-
libsaml-dev
-
3.2.1-1ubuntu0.1
-
libsaml12
-
3.2.1-1ubuntu0.1
-
opensaml-schemas
-
3.2.1-1ubuntu0.1
-
opensaml-tools
-
3.2.1-1ubuntu0.1
Ubuntu 20.04
-
libsaml-dev
-
3.0.1-1ubuntu0.1
-
libsaml10
-
3.0.1-1ubuntu0.1
-
opensaml-schemas
-
3.0.1-1ubuntu0.1
-
opensaml-tools
-
3.0.1-1ubuntu0.1
Ubuntu 18.04
-
libsaml2-dev
-
2.6.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libsaml9
-
2.6.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
opensaml2-schemas
-
2.6.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
opensaml2-tools
-
2.6.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
libsaml2-dev
-
2.5.5-1ubuntu0.1+esm1
Available with Ubuntu Pro
-
libsaml8v5
-
2.5.5-1ubuntu0.1+esm1
Available with Ubuntu Pro
-
opensaml2-schemas
-
2.5.5-1ubuntu0.1+esm1
Available with Ubuntu Pro
-
opensaml2-tools
-
2.5.5-1ubuntu0.1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.