漏洞描述翻译: MojoX::Authentication 在 Perl 环境下 0.006 之前的版本存在 SAML 认证绕过漏洞,原因是 在构建 时未指定信任锚点(trust anchor)。 具体技术细节如下: 在 的 中,代码调用 时未传入 、 或 参数,随后将返回的 XML 传递给 ,并仅使用身份提供方(IdP)的签名证书作为 。然而,在 0.86 版本之前,该证书仅用于校验加密的断言(assertion)。因此,对于未加密的断言,其签名会直接与响应(response)中自带的证书进行比对验证。 攻击流程
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 0 ~ 0.006 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet