Hacker News with Generative AI: SAML

Ruby-SAML pwned by XML signature wrapping attacks (ssoready.com)
CVE-2024-45409 was published on September 10, 2024. It’s yet another XML signature wrapping attack, this time affecting the main Ruby implementation of SAML. The vuln allows an attacker log in as any arbitrary user of the affected system.
Visual explanation of SAML authentication (2020) (sheshbabu.com)
A Gentle Introduction to SAML (ssoready.com)