Web Hack List

Later archive addition

GitHub Enterprise SAML Authentication Bypass

Explains GitHub Enterprise SAML authentication failures caused by differences between the assertions validated for signatures and those consumed after decryption. Reconstructs the vulnerable processing order and a subsequent bypass, with disclosure context acknowledging an earlier private report.

Record

Researcher
Harsh Jaiswal and Rahul Maini
Published by
ProjectDiscovery

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Harsh Jaiswal and Rahul Maini, first published at the original source. Preserved copies are kept so the citation survives its host.