Web Hack List

Collected research

Duo Finds SAML Vulnerabilities Affecting Multiple Implementations

XML canonicalization strips comments before a SAML signature is verified, while many XML text extraction APIs return only the text before the first comment. Inserting a comment inside a signed NameID therefore leaves the signature valid but changes the identity the service provider reads, letting an authenticated attacker log in as any other user.

Record

Researcher
Kelby Ludwig
Published by
Duo Security
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Kelby Ludwig, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .