The Fragile Lock: Novel Bypasses For SAML Authentication
PortSwigger Research·
Originalartikel lesen bei PortSwigger ResearchTLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi