Zendesk · Zendesk Samlr · CVE-2018-20857
Name of the Vulnerable Software and Affected Versions:
Zendesk Samlr versions prior to 2.6.2
Description:
The issue allows an XML nodes comment attack, where an attacker can manipulate the `name id` node by including a comment (`<!---->`) followed by the attacker's domain name, potentially allowing for malicious activities. This can be initiated by setting up a `name id` node with an email address, such as `user@example.com`, followed by the comment and the attacker's domain.
Recommendations:
For versions prior to 2.6.2, update to version 2.6.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of XML nodes comments in the `name id` node to minimize the risk of exploitation.