Опубликовано: 11 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 9.9
CVSS3: 10
Описание
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17.
Ссылки
- https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2
- https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-cvp8-5r8g-fhvq
- https://github.com/omniauth/omniauth-saml/commit/4274e9d57e65f2dcaae4aa3b2accf831494f2ddd
- https://github.com/omniauth/omniauth-saml/commit/6c681fd082ab3daf271821897a40ab3417382e29
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-saml/GHSA-cvp8-5r8g-fhvq.yml
Пакеты
Наименование
omniauth-saml
rubygems
Затронутые версииВерсия исправления
>= 2.0.0, < 2.1.2
2.1.2
Наименование
omniauth-saml
rubygems
Затронутые версииВерсия исправления
< 1.10.5
1.10.5
Наименование
omniauth-saml
rubygems
Затронутые версииВерсия исправления
>= 2.2.0, < 2.2.1
2.2.1
9.9 Critical
CVSS4
10 Critical
CVSS3
Дефекты
CWE-347
9.9 Critical
CVSS4
10 Critical
CVSS3
Дефекты
CWE-347