Product
A vulnerability in Picketlink's SAML Service Provider (SP) signature validation logic allows unauthenticated actors to forge SAML assertions and authenticate as arbitrary users.