Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities (CVE-2025-25291 + CVE-2025-25292) were discovered in ruby-saml up to version 1.17.0. In this blog post, we'll shed light on how
https://t.co/oKrbfVQhEn
It makes me really sad each time I read about the Golder SAML / Silver SAML attack techniques from people/companies working in the "cybersecurity" area.
Let me explain why ⬇️⬇️⬇️
#saml#cybersecurity
If you manage to deceive the app's administrator and the public key start to be trusted by the app, you will now be able to enter the app by generating SAML messages and signing them with the related private key you possess.
@Jaimefdez735@JamesHYPE Pues ya tuvo que liarla en Amsterdam...pq el sonido de la B3 del Viernes...en Pandora hubiera estado mejor, por no hablar del calor que pasamos.
@Emi_Rock75@bernar_sf Los Arcos - McDonalds
Reina Mercedes - Royal Mail
Los Pajaritos - Twitter / Netsle
Tres mil viviendas - Mil anuncios
Vacie / Solvia (con la a de vacie negra)
@Emi_Rock75@bernar_sf@bernar_sf
Porvenir - Polo Ralph Lauren
La Palmera - Malibu drinks
Pino Montano - Four Seasons/Timberland
Ciudad Jardin - Herbalife
Rochelambert - Roche