OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [security-services] Fwd: SAML Security Bypass


On 7/6/20, 2:42 PM, "security-services@lists.oasis-open.org on behalf of Chet Ensign" <security-services@lists.oasis-open.org on behalf of chet.ensign@oasis-open.org> wrote:

> The actual vulnerability appears to be in the PAN-OS software itself when using a particular configuration of SAML. It
> doesn't seem to present a vulnerability in the spec itself. 

Not unless we consider "programmers with no business implementing security standards" a vulnerability. Unfortunately that one's not going away.

-- Scott
 



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]