VDB
Sign up
CRITICAL

GHSA-hw46-3hmr-x9xv

omniauth-saml has dependency on ruby-saml version with Signature Wrapping Attack issue

Quick fix

GHSA-hw46-3hmr-x9xv — omniauth-saml: upgrade to the fixed version with the command below.

bundle update omniauth-saml

Details

### Summary There are 2 new Critical Signature Wrapping Vulnerabilities (CVE-2025-25292, CVE-2025-25291) and a potential DDOS Moderated Vulneratiblity (CVE-2025-25293) affecting ruby-saml, a dependency of omniauth-saml.

The fix will be applied to ruby-saml and released 12 March 2025, under version 1.18.0.

Please [upgrade](https://github.com/omniauth/omniauth-saml/blob/master/omniauth-saml.gemspec#L16) the ruby-saml requirement to v1.18.0.

### Impact Signature Wrapping Vulnerabilities allows an attacker to impersonate a user.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/omniauth-saml
Introduced in: 2.2.0Fixed in: 2.2.3
Fixbundle update omniauth-saml
RubyGems/omniauth-saml
Introduced in: 2.0.0Fixed in: 2.1.3
Fixbundle update omniauth-saml
RubyGems/omniauth-saml
Introduced in: 0Fixed in: 1.10.6
Fixbundle update omniauth-saml

References