VDB
Sign up
CRITICAL9.8

GHSA-4vc4-m8qh-g8jm

Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)

Quick fix

GHSA-4vc4-m8qh-g8jm — ruby-saml: upgrade to the fixed version with the command below.

bundle update ruby-saml

Details

### Summary An authentication bypass vulnerability was found in ruby-saml due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack.

### Impact This issue may lead to authentication bypass.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/ruby-saml
Introduced in: 0Fixed in: 1.12.4
Fixbundle update ruby-saml
RubyGems/ruby-saml
Introduced in: 1.13.0Fixed in: 1.18.0
Fixbundle update ruby-saml

References