Collected research
SAML roulette: the hacker always wins
Ruby-SAML validates with one XML parser and reads attributes with another, so a round-trip mutation in a system identifier, and namespace confusion built from duplicate declarations the first parser wrongly permits, make the two see different signature and digest nodes. Paired with a signature lifted from public federation metadata this yields unauthenticated admin access to GitLab Enterprise.
Record
- Researcher
- Gareth Heyes and Zakhar Fedotkin
- Published by
- PortSwigger Research
- Date
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes and Zakhar Fedotkin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .