USN-8768-1: Shibboleth vulnerability

Publication date

15 September 2026

Overview

Shibboleth could be made to expose sensitive information over the network.


Packages

Details

Florian Stuhlmann discovered that Shibboleth incorrectly escaped input
when using the ODBC storage plugin. A remote attacker could possibly use
this issue to perform SQL injection attacks and obtain sensitive
information.

Florian Stuhlmann discovered that Shibboleth incorrectly escaped input
when using the ODBC storage plugin. A remote attacker could possibly use
this issue to perform SQL injection attacks and obtain sensitive
information.

Update instructions

After a standard system update you need to restart shibboleth-sp to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 LTS noble libshibsp11t64 –  3.4.1+dfsg-2.1ubuntu0.1~esm1  
shibboleth-sp-common –  3.4.1+dfsg-2.1ubuntu0.1~esm1  
shibboleth-sp-utils –  3.4.1+dfsg-2.1ubuntu0.1~esm1  
22.04 LTS jammy libshibsp10 –  3.3.0+dfsg1-1ubuntu0.1~esm1  
shibboleth-sp-common –  3.3.0+dfsg1-1ubuntu0.1~esm1  
shibboleth-sp-utils –  3.3.0+dfsg1-1ubuntu0.1~esm1  
20.04 LTS focal libshibsp8 –  3.0.4+dfsg1-1ubuntu0.2+esm1  
shibboleth-sp-common –  3.0.4+dfsg1-1ubuntu0.2+esm1  
shibboleth-sp-utils –  3.0.4+dfsg1-1ubuntu0.2+esm1  
shibboleth-sp2-common –  3.0.4+dfsg1-1ubuntu0.2+esm1  
shibboleth-sp2-utils –  3.0.4+dfsg1-1ubuntu0.2+esm1  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›