Outage in OpenAthens

Advisory for OpenAthens customers using custom SAML resources.

Minor
March 18, 2025 - Started about 1 month ago
Official incident page

Need to monitor OpenAthens outages?
Stay on top of outages with IsDown. Monitor the official status pages of all your vendors, SaaS, and tools, including OpenAthens, and never miss an outage again.
Start Free Trial

Outage Details

Institutional customers using custom SAML resources in OpenAthens should be aware of security vulnerabilities in Shibboleth Service Provider software and SimpleSAML Service Provider software which might affect the vendors they are connecting with. What you need to do: We suggest institutional customers using custom SAML resources in OpenAthens send these links to their vendors and ask them to confirm their Service Provider software is either unaffected or that the vulnerability has been addressed. To find the resources, please go into the admin area and look at the custom tab within the resource catalogue, you only need to concern yourself with the ones that say SAML. You can find more information here: https://shibboleth.net/pipermail/announce/2025-March/000337.html https://simplesamlphp.org/security/202501-01 For the avoidance of doubt: these vulnerabilities do NOT affect the OpenAthens service. Please direct all queries to the vendors for which your institution is using custom SAML resources in OpenAthens.
Latest Updates ( sorted recent to last )
IDENTIFIED about 1 month ago - at 03/18/2025 03:18PM

Institutional customers using custom SAML resources in OpenAthens should be aware of security vulnerabilities in Shibboleth Service Provider software and SimpleSAML Service Provider software which might affect the vendors they are connecting with.

What you need to do: We suggest institutional customers using custom SAML resources in OpenAthens send these links to their vendors and ask them to confirm their Service Provider software is either unaffected or that the vulnerability has been addressed. To find the resources, please go into the admin area and look at the custom tab within the resource catalogue, you only need to concern yourself with the ones that say SAML.

You can find more information here:
https://shibboleth.net/pipermail/announce/2025-March/000337.html
https://simplesamlphp.org/security/202501-01

For the avoidance of doubt: these vulnerabilities do NOT affect the OpenAthens service. Please direct all queries to the vendors for which your institution is using custom SAML resources in OpenAthens.

Latest OpenAthens outages

Service Outage - P1 - 3 months ago
Service Outage - P2 - 4 months ago

Real-time vendor status monitoring for IT and Ops teams

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 3965 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook