SAML roulette: the hacker always wins
portswigger.net | research | #gitlab | #authentication-bypass | #xml | #saml | #round-trip | #namespace-confusion
Summary
Chaining XML round-trip attacks and namespace confusion yields unauthenticated admin access on GitLab Enterprise via ruby-saml, using comment and CDATA mutations that defeat signature verification.
- Published
- Collected
Skip to content