Логотип exploitDog
bind:CVE-2025-25293
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-25293

Количество 5

Количество 5

ubuntu логотип

CVE-2025-25293

11 месяцев назад

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-25293

11 месяцев назад

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-25293

11 месяцев назад

ruby-saml provides security assertion markup language (SAML) single si ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-92rq-c8cf-prrq

11 месяцев назад

Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-03642

11 месяцев назад

Уязвимость протокола единого входа SAML SSO библиотеки Ruby SAML, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-25293

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.

CVSS3: 7.5
3%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-25293

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.

CVSS3: 7.5
3%
Низкий
11 месяцев назад
debian логотип
CVE-2025-25293

ruby-saml provides security assertion markup language (SAML) single si ...

CVSS3: 7.5
3%
Низкий
11 месяцев назад
github логотип
GHSA-92rq-c8cf-prrq

Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses

CVSS3: 7.5
3%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-03642

Уязвимость протокола единого входа SAML SSO библиотеки Ruby SAML, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
3%
Низкий
11 месяцев назад

Уязвимостей на страницу