HIGH7.7RubyGems
GHSA-94hm-8q65-rmxm· CVE-2017-11430OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
Modified: 2/16/2024
package
pkg:rubygems/omniauth-saml
OmniAuth-SAML authentication bypass via incorrect XML canonicalization and DOM traversal
Modified: 2/16/2024
omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
Modified: 8/7/2026
omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue
Modified: 2/4/2026