CVE-2024-45409
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/09/2024
Last modified:
20/09/2024
Description
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* | 1.12.3 (excluding) | |
cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* | 1.13.0 (including) | 1.17.0 (excluding) |
cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:* | 1.10.3 (including) | |
cpe:2.3:a:omniauth:omniauth_saml:2.0.0:*:*:*:*:ruby:*:* | ||
cpe:2.3:a:omniauth:omniauth_saml:2.1.0:*:*:*:*:ruby:*:* | ||
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | 16.11.10 (excluding) | |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | 17.0.0 (including) | 17.0.8 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | 17.1.0 (including) | 17.1.8 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | 17.2.0 (including) | 17.2.7 (excluding) |
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | 17.3.0 (including) | 17.3.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/SAML-Toolkits/ruby-saml/commit/1ec5392bc506fe43a02dbb66b68741051c5ffeae
- https://github.com/SAML-Toolkits/ruby-saml/commit/4865d030cae9705ee5cdb12415c654c634093ae7
- https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2
- https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-cvp8-5r8g-fhvq