SAML-Toolkits / java-saml

Java SAML toolkit
MIT License
634 stars 398 forks source link

Updated org.apache.santuario:xmlsec to version 2.3.0 #377

Closed haavar closed 2 years ago

haavar commented 2 years ago

Updating xmlsec to avoid pulling in a version of woodstox-core that is vulnerable to Improper Restriction of XML eXternal Entity (XXE) Reference,

pitbulk commented 2 years ago

@bzvestey run the test and feel free to merge if them pass

bzvestey commented 2 years ago

@eriktalvi FYI

LivingInSyn commented 2 years ago

@bzvestey When can we expect a release with this in it?