Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92rq-c8cf-prrq

Опубликовано: 12 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses

Summary

ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses.

Ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after.

Impact

This issue may lead to remote Denial of Service (DoS).

Пакеты

Наименование

ruby-saml

rubygems
Затронутые версииВерсия исправления

< 1.12.4

1.12.4

Наименование

ruby-saml

rubygems
Затронутые версииВерсия исправления

>= 1.13.0, < 1.18.0

1.18.0

EPSS

Процентиль: 86%
0.02704
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.

CVSS3: 7.5
nvd
11 месяцев назад

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.

CVSS3: 7.5
debian
11 месяцев назад

ruby-saml provides security assertion markup language (SAML) single si ...

CVSS3: 7.5
fstec
11 месяцев назад

Уязвимость протокола единого входа SAML SSO библиотеки Ruby SAML, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 86%
0.02704
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770