-
Notifications
You must be signed in to change notification settings - Fork 79
Closed
Description
Hi @tobiashort,
Hope you are doing well.
I’d like to propose implementing two new CVEs: CVE-2025-25291 and CVE-2025-25292. If you want to read more about vulnerabilities - write up is available here https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/
Would you be interested in having this added to the SAMLRaider extension?
If so, I’m happy to handle the implementation. I can make a test environment similar to the previous one, so you can easily reproduce issue.
Looking forward to hearing your thoughts!
Cheers
Metadata
Metadata
Assignees
Labels
No labels