peter bassill · operator
$ cve CVE-2024-45409 JSON

CVE-2024-45409

10.0
CRITICAL · CVSS 3.1 · EPSS 10.7% (pctl 96)

Patch early

EPSS 10.7% — above the 10% action threshold.

Description

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS10.68% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-347
On CISA KEVno
Public exploitnone known
Published2024-09-10
Last modified2026-06-17

Affected (3)

VendorProduct
gitlabgitlab
omniauthomniauth saml
oneloginruby-saml

References

→ the Explorer  ·  watch your stack  ·  NVD