saml

3 articles
sort: new top best
clear filter
0 7/10

A critical Slack SAML authentication bypass vulnerability caused by failure to validate the Audience restriction element in SAML assertions, allowing attackers to present assertions meant for other service providers (e.g., expired Github assertions) to gain unauthorized access to Slack accounts. The vulnerability exploited the "confused deputy problem" and was reported and patched in 2017.

Slack SAML Raider Ioannis Kakavas Github HackerOne Max Feldman CVE-2016-0701
blog.intothesymmetry.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 7/10

Security researcher discovered an SSRF vulnerability in Yahoo! Guesthouse by finding a SAML endpoint through recon, then exploiting the BouncerSAMLRemoteSessionHost cookie which accepted arbitrary hostname values, causing the backend to make requests to attacker-controlled servers.

Yahoo! Guesthouse Th3G3nt3lman BouncerSAMLRemoteSessionHost https://gh.bouncer.login.yahoo.com/ https://alpha.keyserver.yahoo.com/saml dip2.gq1.yahoo.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 1/10

Parevo Core is a modular Go library that consolidates authentication, multi-tenancy, and permission management (RBAC/ABAC) across common web frameworks and databases. It provides auth primitives (JWT, OAuth2, SAML, LDAP, WebAuthn), tenant isolation with SQL filters, and pluggable storage adapters for MySQL, Postgres, MongoDB, and Redis.

Parevo Core Go
github.com · parevo · 22 hours ago · details · hn