<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Bypass in SAML Authentication. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-bypass-in-saml-authentication/m-p/336502#M84762</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105432"&gt;@karthikeyanB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While this would be an alternative, I assume protecting from this authentication bypass vulnerability with a signature is difficult, maybe even impossible as there - as far as I understand the securityadvisory - isn't some 'malicious' in the traffic that can be blocked. The traffic looks like a normal authentication request and the problem (the vulnerability) is that PAN-OS does not correctly verify the signature of the SAML assertion.&lt;/P&gt;
&lt;P&gt;So if you are affected, do not wait and install the update as soon as possible or make sure the option "&lt;SPAN&gt;Validate Identity Provider Certificate" is enabled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Remo&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jul 2020 20:21:35 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2020-07-02T20:21:35Z</dc:date>
    <item>
      <title>Authentication Bypass in SAML Authentication.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-bypass-in-saml-authentication/m-p/336495#M84761</link>
      <description>&lt;DIV&gt;&lt;SPAN&gt;Dear Support Team,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Please do us favour to update Security appliance Palo Alto with latest signature which help to prevent from latest vulnerability&amp;nbsp;Authentication Bypass in SAML Authentication.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;&lt;SPAN&gt;Patch requirement for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;CVE-2020-2021 PAN-OS: Authentication Bypass in SAML Authentication&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;&lt;SPAN&gt;Karthikeyan Balamurugan&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Jul 2020 18:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-bypass-in-saml-authentication/m-p/336495#M84761</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2020-07-02T18:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Bypass in SAML Authentication.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-bypass-in-saml-authentication/m-p/336502#M84762</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/105432"&gt;@karthikeyanB&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While this would be an alternative, I assume protecting from this authentication bypass vulnerability with a signature is difficult, maybe even impossible as there - as far as I understand the securityadvisory - isn't some 'malicious' in the traffic that can be blocked. The traffic looks like a normal authentication request and the problem (the vulnerability) is that PAN-OS does not correctly verify the signature of the SAML assertion.&lt;/P&gt;
&lt;P&gt;So if you are affected, do not wait and install the update as soon as possible or make sure the option "&lt;SPAN&gt;Validate Identity Provider Certificate" is enabled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Remo&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 20:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-bypass-in-saml-authentication/m-p/336502#M84762</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-07-02T20:21:35Z</dc:date>
    </item>
  </channel>
</rss>

