A vulnerability has been reported in OpenSAML, which can be exploited by malicious people to bypass certain security features. The vulnerability is caused due to the library not properly verifying certain signed XML messages, which can be exploited to bypass the verification via "wrapping attacks".The vulnerability is reported in versions prior to 2.4.3 of the C library and versions prior to 2.5.1 of the Java library.
Solution:
Update to version 2.4.3 of the OpenSAML C library. Update to version 2.5.1 of the OpenSAML Java library when available.