XML External Entity (XXE) vulnerability

Tom Scavo trscavo at gmail.com
Mon Feb 23 18:14:15 EST 2015


On Mon, Feb 23, 2015 at 6:04 PM, Daniel Fisher <dfisher at vt.edu> wrote:
> On Mon, Feb 23, 2015 at 5:24 PM, Tom Scavo <trscavo at gmail.com> wrote:
>>
>> Not sure if I should send this under the radar but here's a blog post
>> that claims there's a vulnerability in some OpenSAML code on the wiki:
>>
>> http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and-the-dangers-of-saml
>
> I believe this hit the users list some time ago.
>
> http://shibboleth.1660669.n2.nabble.com/web-based-single-sign-on-and-the-dangers-of-saml-xml-td7592366.html

Thanks Daniel. I didn't realize this is over a year old.

Tom


More information about the dev mailing list