2 Videos for SAML: CVE-2021-21239

PRO
Tier
Medium
2-4 Hrs.
74
image of exercise CVE-2021-21239: Introduction
Access to videos for this exercise is only available with PentesterLab PRO GOPRO
CVE-2021-21239: Introduction

In this video, we introduce the CVE-2021-21239 challenge as part of the authentication and authorization badge. We discuss the SAML response structure, its signing process, and the vulnerability that allows bypassing trust by embedding a key directly in the signed information.

video duration icon05:26 number of views icon294

 

image of exercise CVE-2021-21239: Exploitation
Access to videos for this exercise is only available with PentesterLab PRO GOPRO
Spoiler
CVE-2021-21239: Exploitation

In this video, we explore the exploitation of CVE-2021-21239, a vulnerability in XMLSec that allows attackers to manipulate SAML responses by prioritizing key-value elements over pre-configured certificates. This enables unauthorized access by signing messages with a controlled RSA key.

video duration icon07:13 number of views icon457