ahacker1
7 exploits
Active since Sep 2024
ruby-saml <=1.12.2 and 1.13.0-1.16.0 - Unauthenticated SAML Signature Verification Bypass
CVSS 10.0
xml-crypto < 6.0.1, 3.0.0-3.2.0, < 2.1.6 - Cryptographic Signature Verification Bypass
xml-crypto < 6.0.1, 3.0.0-3.2.1, < 2.1.6 - Cryptographic Signature Verification Bypass
samlify < 2.10.0 - Signature Wrapping Attack via SAML Response Forgery
CVSS 7.5
SignXML < 4.0.4 - Observable Timing Discrepancy in HMAC Verification
node-saml < 5.1.0 - Improper Verification of Cryptographic Signature
node-saml < 5.1.0 - Authentication Bypass via SAML Assertion Manipulation
CVSS 10.0