OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Fwd: SAML Security Bypass



Members of the SAML TC,Â

Patrick Duruseau forwarded this to me last Thursday and I want to make sure you are aware of it.Â

The actual vulnerability appears to be in the PAN-OS software itself when using a particular configuration of SAML. It doesn't seem to present a vulnerability in the spec itself.Â

But I did want to make sure you were aware of it. If it does seem to involve SAML in any way, feel free to contact me about how to respond.Â

Best,Â

/chetÂÂ


---------- Forwarded message ---------
From: Patrick Durusau <patrick@durusau.net>
Date: Thu, Jul 2, 2020 at 3:53 PM
Subject: SAML Security Bypass
To: Chet Ensign <chet.ensign@oasis-open.org>


Chet,

I know you have been all over this but I ran across this blog today
while searching for something else:

https://www.trustedsec.com/blog/cve-2020-2021-pan-os-saml-security-bypass/

Hope you are having a great week!

Patrick

--
Patrick Durusau
patrick@durusau.net
Technical Advisory Board, OASIS (TAB)
Editor, OpenDocument Format TC (OASIS), Project Editor ISO/IEC 26300
Co-Editor, ISO/IEC 13250-1, 13250-5 (Topic Maps)

Another Word For It (blog): http://tm.durusau.net
Homepage: http://www.durusau.net
Twitter: patrickDurusau




--

/chetÂ
----------------
Chet Ensign
Chief Technical Community Steward
OASIS: Advancing open source & open standards for the information society
http://www.oasis-open.org

Mobile: +1 201-341-1393Â
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtRkOMt7ClSedU93TU8ayCLcyDJwFAl7+Oz0ACgkQU8ayCLcy
DJwY3Q//X/xvi7BnG8hFm59mB7EmLrirnTHaO9+RUb75yTd1gL3VbeOr8uL3FwNe
WSgMVMk3Kh+a5cBrqsShz1G2au25UWOEyXpDj67VfVFtVh4QMsZDH+wvfw+ecO1b
HwyGJobvXm1myHF3NAZ7nFrnsTvAdhKxNNQgc1y+FRNGeU7w0qt0qXQla6McAVfY
ulCj3SYX+sELy3ed3iXDy7xDFfIvQILb8Y55YWUH5/Cp+As1JXoXVujGTBC5TQ3m
qPemcoDVXdnWPotoW8/vlcpnTtv3w4iRcZtBtC4Q9NccHP4/jaPr/FBrRy4pJzIG
JUTDgUt4WQKdkdJGGJT2Tn1PD/ZrjBcxg1qhg8Pb+ozebiorJbRcqmsZooC+/GjG
gD8prFPTIq7qfwNybwDRiBRXRUqH7jsv9K06jPnqU9btfqGD3kUZv66ZAFERDywR
sHArVb+4n+ZEwH/nsL7SHhj2ya+7Ljef9oePVa+Kc9QsG3QRPcFnkyWeeGSQuvPS
Gj/6TP2n6z0tzsgI1aWsofI6wxXg4QDYrbMBROiRf0rjRoA0f2lYbyQlXG5YMDux
T42IZlMXbqt/m6wil1zZ/3fq0UKil68ik2wW8tvOKYzmK7TfU5DaLd8oIBt8Af5b
BcTLVwBq/d6oP1AWomP/MaEuAJpXqswD89vBUfeLmrL9pqcBGpM=
=ZnQt
-----END PGP SIGNATURE-----


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]