← Back to feed
research PortSwigger Research

SAML roulette: the hacker always wins

PortSwigger Research GitLab

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Ent...

Read the full story PortSwigger Research →

Related Coverage

research HTTP/3 in Burp Suite - it’s time to find a bigger wordlist PortSwigger Research · Sep 23 research The Lure Isn't The Malware. It's Your Logo. Recorded Future · Sep 23 research Looking for free Robux? Here’s what’s real, and what’s a scam ESET Research · Sep 22