zendesk / samlr

Clean room implementation of SAML for Ruby
Apache License 2.0
30 stars 12 forks source link

backporting samlr vuln fix from zendesk_auth #29

Closed swatikri closed 5 years ago

swatikri commented 5 years ago

This PR is just porting a vulnerability fix into samlr Todo

greysteil commented 5 years ago

Thanks for this fix, and for samlr.

I work on the GitHub Security Workflows team and we were alerted to this change when it appeared in the NVD feed of CVEs (here). If you've got 5 minutes I'd love some feedback from you on how GitHub can help in situations like this.

In particular, I'd love to know:

Any feedback you can provide (even if it's just "I had no idea about any of this") would be super valuable. Thanks!