Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
Discussion around the web
- Hacker News312 · 124 💬
Score breakdown
- Technical depth85
- Practical value60
- Originality85
- Writing quality82
- Source reputation85
- Recency0
- External engagement35
- On-site engagement0
More like this
The Cloudflare Blog52
Keyless SSL: The Nitty Gritty Technical Details
unknown·26 min read
The Cloudflare Blog59
Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH
unknown·15 min read
Airbnb Engineering59
Flexible Authentication: Reimagining authentication for millions of users at Airbnb
Jose Santos·unknown·8 min read
The GitHub Blog61
Behind GitHub's new authentication token formats
Indigo K·unknown·11 min read
Engradar shows a summary and links to the original article. The full article is hosted on github.blog.