CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for do...Show more |
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292....Show more |
2Omniauth Onelogin2Omniauth Saml Ruby SamlJun 17, 2026 Mar 12, 2025 7.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses....Show more |
3Netapp OmniauthOnelogin3Omniauth Saml Ruby SamlStoragegridJun 17, 2026 Mar 12, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential....Show more |
3Netapp OmniauthOnelogin3Omniauth Saml Ruby SamlStoragegridJun 17, 2026 Mar 12, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential....Show more |
3Gitlab OmniauthOnelogin3Gitlab Omniauth SamlRuby SamlJun 17, 2026 Sep 10, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with a...Show more |
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used. |
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryp...Show more |
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. |