omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Critical severity
GitHub Reviewed
Published
Sep 11, 2024
in
omniauth/omniauth-saml
•
Updated Sep 19, 2024
Package
Affected versions
>= 2.0.0, < 2.1.2
< 1.10.5
>= 2.2.0, < 2.2.1
Patched versions
2.1.2
1.10.5
2.2.1
Description
Published to the GitHub Advisory Database
Sep 11, 2024
Reviewed
Sep 11, 2024
Last updated
Sep 19, 2024
ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see GHSA-jw9c-mfg7-9rx2
As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17.
References