{"id":"GHSA-hw46-3hmr-x9xv","summary":"omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue","details":"### Summary\nThere are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml.\n\nThe fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0.\n\nPlease [upgrade](https://github.com/omniauth/omniauth-saml/blob/master/omniauth-saml.gemspec#L16) the ruby-saml requirement to v1.18.0.\n\n### Impact\nSignature Wrapping Vulnerabilities allows an attacker to impersonate a user.","modified":"2026-02-04T04:23:01.195729Z","published":"2025-03-12T19:42:58Z","related":["CVE-2025-25291","CVE-2025-25292","CVE-2025-25293"],"database_specific":{"cwe_ids":["CWE-347"],"github_reviewed_at":"2025-03-12T19:42:58Z","github_reviewed":true,"nvd_published_at":null,"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-hw46-3hmr-x9xv"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/commit/0d5eaa0d808acb2ac96deadf5c750ac1cf2d92b5"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/commit/2c8a482801808bbcb0188214bde74680b8018a35"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/commit/7a348b49083462a566af41a5ae85e9f3af15b985"},{"type":"PACKAGE","url":"https://github.com/omniauth/omniauth-saml"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/blob/master/omniauth-saml.gemspec#L16"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-saml/GHSA-hw46-3hmr-x9xv.yml"},{"type":"WEB","url":"https://rubygems.org/gems/omniauth-saml/versions/2.2.3"}],"affected":[{"package":{"name":"omniauth-saml","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.3"}]}],"versions":["2.2.0","2.2.1","2.2.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-hw46-3hmr-x9xv/GHSA-hw46-3hmr-x9xv.json"}},{"package":{"name":"omniauth-saml","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.1.3"}]}],"versions":["2.0.0","2.1.0","2.1.1","2.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-hw46-3hmr-x9xv/GHSA-hw46-3hmr-x9xv.json"}},{"package":{"name":"omniauth-saml","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.6"}]}],"versions":["0.9.0","0.9.1","0.9.2","1.0.0","1.1.0","1.10.0","1.10.1","1.10.2","1.10.3","1.10.4","1.10.5","1.2.0","1.3.0","1.3.1","1.4.0","1.4.1","1.4.2","1.5.0","1.6.0","1.7.0","1.8.0","1.8.1","1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-hw46-3hmr-x9xv/GHSA-hw46-3hmr-x9xv.json"}}],"schema_version":"1.7.3"}