Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jw9c-mfg7-9rx2

Опубликовано: 10 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 9.9
CVSS3: 10

Описание

SAML authentication bypass via Incorrect XPath selector

Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system.

This vulnerability was reported by ahacker1 of SecureSAML (ahacker1@securesaml.com)

Пакеты

Наименование

ruby-saml

rubygems
Затронутые версииВерсия исправления

< 1.12.3

1.12.3

Наименование

ruby-saml

rubygems
Затронутые версииВерсия исправления

>= 1.13.0, < 1.17.0

1.17.0

EPSS

Процентиль: 94%
0.14907
Средний

9.9 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 10
ubuntu
9 месяцев назад

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

CVSS3: 10
nvd
9 месяцев назад

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

CVSS3: 10
debian
9 месяцев назад

The Ruby SAML library is for implementing the client side of a SAML au ...

CVSS3: 10
fstec
9 месяцев назад

Уязвимость реализации модуля единого входа в приложения SAML библиотеки Ruby SAML и программной платформы на базе git для совместной работы над кодом GitLab, позволяющая повысить свои привилегии

EPSS

Процентиль: 94%
0.14907
Средний

9.9 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-347