XML External Entity (XXE) vulnerability
Daniel Fisher
dfisher at vt.edu
Mon Feb 23 18:04:26 EST 2015
On Mon, Feb 23, 2015 at 5:24 PM, Tom Scavo <trscavo at gmail.com> wrote:
> Not sure if I should send this under the radar but here's a blog post
> that claims there's a vulnerability in some OpenSAML code on the wiki:
>
>
> http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and-the-dangers-of-saml
I believe this hit the users list some time ago.
http://shibboleth.1660669.n2.nabble.com/web-based-single-sign-on-and-the-dangers-of-saml-xml-td7592366.html
--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20150223/09ae4333/attachment.html
More information about the dev
mailing list