zendesk/samlr

zendesk/samlr

Releases52
Frequency3 months 6 days
Last Release
Stars29
Clean room implementation of SAML for Ruby

CVE History

CVEPublishedCVSS v3CVSS v2
5 MEDIUM

Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with [email protected] followed by <!---->. and then the attacker's domain name.