{"id":"GHSA-94hm-8q65-rmxm","summary":"OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal","details":"OmniAuth OmniAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.","aliases":["CVE-2017-11430"],"modified":"2024-02-16T08:19:52.688707Z","published":"2019-07-05T21:11:43Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:27:27Z","nvd_published_at":null,"cwe_ids":["CWE-287"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11430"},{"type":"WEB","url":"https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations"},{"type":"PACKAGE","url":"https://github.com/omniauth/omniauth-saml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-saml/CVE-2017-11430.yml"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/475445"}],"affected":[{"package":{"name":"omniauth-saml","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.0"}]}],"versions":["0.9.0","0.9.1","0.9.2","1.0.0","1.1.0","1.2.0","1.3.0","1.3.1","1.4.0","1.4.1","1.4.2","1.5.0","1.6.0","1.7.0","1.8.0","1.8.1","1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-94hm-8q65-rmxm/GHSA-94hm-8q65-rmxm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}