2 Videos for SAML: CVE-2021-21239

Access to videos for this exercise is only available with PentesterLab PRO
GOPRO
CVE-2021-21239: Introduction
In this video, we introduce the CVE-2021-21239 challenge as part of the authentication and authorization badge. We discuss the SAML response structure, its signing process, and the vulnerability that allows bypassing trust by embedding a key directly in the signed information.

Access to videos for this exercise is only available with PentesterLab PRO
GOPRO
CVE-2021-21239: Exploitation
In this video, we explore the exploitation of CVE-2021-21239, a vulnerability in XMLSec that allows attackers to manipulate SAML responses by prioritizing key-value elements over pre-configured certificates. This enables unauthorized access by signing messages with a controlled RSA key.