{"id":"GHSA-cvp8-5r8g-fhvq","summary":"omniauth-saml vulnerable to Improper Verification of Cryptographic Signature","details":"ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in \u003c= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 \nAs a result, omniauth-saml created a [new release](https://github.com/omniauth/omniauth-saml/releases) by upgrading ruby-saml to the patched versions v1.17. \n","modified":"2026-08-07T08:11:59.192768697Z","published":"2024-09-11T21:08:26Z","related":["CVE-2024-45409"],"database_specific":{"cwe_ids":["CWE-347"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-09-11T21:08:26Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-cvp8-5r8g-fhvq"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/commit/4274e9d57e65f2dcaae4aa3b2accf831494f2ddd"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/commit/6c681fd082ab3daf271821897a40ab3417382e29"},{"type":"PACKAGE","url":"https://github.com/omniauth/omniauth-saml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-saml/GHSA-cvp8-5r8g-fhvq.yml"}],"affected":[{"package":{"name":"omniauth-saml","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.1.2"}]}],"versions":["2.0.0","2.1.0","2.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-cvp8-5r8g-fhvq/GHSA-cvp8-5r8g-fhvq.json"}},{"package":{"name":"omniauth-saml","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.5"}]}],"versions":["0.9.0","0.9.1","0.9.2","1.0.0","1.1.0","1.10.0","1.10.1","1.10.2","1.10.3","1.10.4","1.2.0","1.3.0","1.3.1","1.4.0","1.4.1","1.4.2","1.5.0","1.6.0","1.7.0","1.8.0","1.8.1","1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-cvp8-5r8g-fhvq/GHSA-cvp8-5r8g-fhvq.json"}},{"package":{"name":"omniauth-saml","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.1"}]}],"versions":["2.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-cvp8-5r8g-fhvq/GHSA-cvp8-5r8g-fhvq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"}]}