Ubuntu Security Notice 4925-1 - Toni Huttunen and Fraktal Oy discovered that the Shibboleth Service provider allowed content injection due to allowing attacker-controlled parameters in error or other status pages. An attacker could use this to inject malicious content.
6ad6f608a285dacbd171aa3b9be8cc237c897d08f93bc06eae2531fcf9bbea12