VDB
Sign up
HIGH7.5

GHSA-92rq-c8cf-prrq

Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses

Quick fix

GHSA-92rq-c8cf-prrq — ruby-saml: upgrade to the fixed version with the command below.

bundle update ruby-saml

Details

### Summary ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses.

Ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after.

### Impact This issue may lead to remote Denial of Service (DoS).

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/ruby-saml
Introduced in: 0Fixed in: 1.12.4
Fixbundle update ruby-saml
RubyGems/ruby-saml
Introduced in: 1.13.0Fixed in: 1.18.0
Fixbundle update ruby-saml

References