SAML roulette: the hacker always wins
CYBERSECURITY FEATURED ANALYSIS

SAML roulette: the hacker always wins

SOURCE

PortSwigger Research

DATE

READ

1 min read

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library