Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use secure version of node-saml #855

Merged
merged 1 commit into from Apr 11, 2023
Merged

Conversation

cjbarth
Copy link
Collaborator

@cjbarth cjbarth commented Apr 11, 2023

Description

node-saml has been updated with a patch release to address a security concern. Set the minimum allowed version of node-saml to make sure we get that security patch.

@cjbarth cjbarth added dependencies Pull requests that update a dependency file security labels Apr 11, 2023
@cjbarth cjbarth merged commit eb65615 into node-saml:master Apr 11, 2023
6 checks passed
@cjbarth cjbarth deleted the security-update branch April 11, 2023 22:50
@markstos
Copy link
Contributor

markstos commented Apr 12, 2023

For those looking for the vuln details:

I'm not sure if these vulns are accessible through passport-saml or not, but considering that we pass through XML to be parsed by these libraries, it's best to presume that they are reachable through passport-saml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants