XML External Entity (XXE) vulnerability
Cantor, Scott
cantor.2 at osu.edu
Mon Feb 23 19:01:21 EST 2015
On 2/23/15, 11:14 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>On Mon, Feb 23, 2015 at 6:04 PM, Daniel Fisher <dfisher at vt.edu> wrote:
>> On Mon, Feb 23, 2015 at 5:24 PM, Tom Scavo <trscavo at gmail.com> wrote:
>>>
>>> Not sure if I should send this under the radar but here's a blog post
>>> that claims there's a vulnerability in some OpenSAML code on the wiki:
>>>
>>>
>>>http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and
>>>-the-dangers-of-saml
>>
>> I believe this hit the users list some time ago.
>>
>>
>>http://shibboleth.1660669.n2.nabble.com/web-based-single-sign-on-and-the-
>>dangers-of-saml-xml-td7592366.html
>
>Thanks Daniel. I didn't realize this is over a year old.
There's also an advisory for it.
http://shibboleth.net/community/advisories/secadv_20131213.txt
-- Scott
More information about the dev
mailing list