← Back to feed
research PortSwigger Research

SAML roulette: the hacker always wins

PortSwigger Research GitLab

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Ent...

Read the full story PortSwigger Research →

Related Coverage

research Agent Running in the Age of AI Recorded Future · Sep 22 research 21st September – Threat Intelligence Report Check Point Research · Sep 21 research SAML: A fractal of bad design Trail of Bits · Sep 21