Web Hack List

Collected research

SAML roulette: the hacker always wins

Ruby-SAML validates with one XML parser and reads attributes with another, so a round-trip mutation in a system identifier, and namespace confusion built from duplicate declarations the first parser wrongly permits, make the two see different signature and digest nodes. Paired with a signature lifted from public federation metadata this yields unauthenticated admin access to GitLab Enterprise.

Record

Researcher
Gareth Heyes and Zakhar Fedotkin
Published by
PortSwigger Research
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes and Zakhar Fedotkin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .