Uninett / mod_auth_mellon

An Apache module with a simple SAML 2.0 service provider

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Question: SAML Response XML Handling

theWizK opened this issue · comments

I'm curious if anyone has investigated mod_auth_mellon to identify if the XML handling of SAML responses is vulnerable to the class of attacks outlined in these articles:

https://www.kb.cert.org/vuls/id/475445
https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations

Obviously, assuming the IdP you're configured to use is not mitigating the vulnerability on their side. It sounds like mitigations on the IdP side may or may not keep you safe depending on a number of scenarios and configurable details on either side...

Thanks.