← Back to feed
AwarenessEmerging1 sourceMar 18, 2025 · 14:55via PortSwigger Research

SAML roulette: the hacker always wins

Brief

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library

Read more on PortSwigger Research