Shibboleth Identity Provider Security Advisory with new minor version release
Posted on Thursday, 28 August 2025
The UK federation recommends adhering to best practices by routinely managing patches for your IdP environment. This includes subscribing to future security notifications:Shibboleth Announce.
Following the recent security advisory from the Shibboleth Consortium regarding the IdP, you should update your Identity Provider software to version 5.1.6 (or later) at your earliest convenience. Although the affected code path is likely not in use by the UK federation userbase, updating will help mitigate any potential exploits.
As ever, please ensure your software versions are patched promptly. If you have any questions or queries then please do contact the UK federation service desk
Audience
While this advisory is directed only at operators of the Shibboleth IdP rather than other entities within the UK federation, it is good practice to be subscribed to the appropriate mailing lists for any software you operate in order to stay abreast of the need for updates.
Edited by SteveGlover on 28 August 2025, at 04:44 PM