脆弱的锁:SAML 认证的新型绕过技术
portswigger.net | 研究 | #appsec | #ruby | #authentication-bypass | #php | #web-security | #saml | #xml-signature | #parser-discrepancies
摘要
SAML 认证再曝严重绕过:攻击者利用属性污染、命名空间混淆及新型 Void Canonicalization 攻击,绕过 XML 签名校验,在 Ruby 与 PHP 生态(含 GitLab EE)实现完全认证绕过。
- 发布时间
- 收录时间
Skip to content