JFrog Artifactory Pro 6.5.9 Signature Validation
Posted by deepcore on March 20, 2019 – 9:40 pm
The SAML SSO addon in JFrog Artifactory version 6.5.9 does not properly validate the XML signature in the SAMLResponse field send to the URL /webapp/saml/loginResponse. An attacker can use this flaw to login as any user if they already can login as some user.
Post a reply
You must be logged in to post a comment.