Omniauth / Omniauth Saml
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-25292 | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential) | CRITICAL | 9.3 | Mar 12, 2025 |
| CVE-2025-25291 | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential) | CRITICAL | 9.3 | Mar 12, 2025 |
| CVE-2025-25293 | ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses | HIGH | 7.7 | Mar 12, 2025 |
| CVE-2024-45409 | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector | CRITICAL | 9.9 | Sep 10, 2024 |
| CVE-2017-11430 | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal | CRITICAL | 9.8 | Apr 17, 2019 |
Showing 1 to 5 of 5 CVEs