Логотип exploitDog
bind:CVE-2024-45409
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45409

Количество 5

Количество 5

ubuntu логотип

CVE-2024-45409

9 месяцев назад

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

CVSS3: 10
EPSS: Средний
nvd логотип

CVE-2024-45409

9 месяцев назад

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

CVSS3: 10
EPSS: Средний
debian логотип

CVE-2024-45409

9 месяцев назад

The Ruby SAML library is for implementing the client side of a SAML au ...

CVSS3: 10
EPSS: Средний
github логотип

GHSA-jw9c-mfg7-9rx2

9 месяцев назад

SAML authentication bypass via Incorrect XPath selector

CVSS3: 10
EPSS: Средний
fstec логотип

BDU:2024-07261

9 месяцев назад

Уязвимость реализации модуля единого входа в приложения SAML библиотеки Ruby SAML и программной платформы на базе git для совместной работы над кодом GitLab, позволяющая повысить свои привилегии

CVSS3: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-45409

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

CVSS3: 10
15%
Средний
9 месяцев назад
nvd логотип
CVE-2024-45409

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

CVSS3: 10
15%
Средний
9 месяцев назад
debian логотип
CVE-2024-45409

The Ruby SAML library is for implementing the client side of a SAML au ...

CVSS3: 10
15%
Средний
9 месяцев назад
github логотип
GHSA-jw9c-mfg7-9rx2

SAML authentication bypass via Incorrect XPath selector

CVSS3: 10
15%
Средний
9 месяцев назад
fstec логотип
BDU:2024-07261

Уязвимость реализации модуля единого входа в приложения SAML библиотеки Ruby SAML и программной платформы на базе git для совместной работы над кодом GitLab, позволяющая повысить свои привилегии

CVSS3: 10
15%
Средний
9 месяцев назад

Уязвимостей на страницу