漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ruby SAML DOS vulnerability with large SAML response
Vulnerability Description
The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting configured. The vulnerability occurs because the SAML response is validated for Base64 format prior to checking the message size, leading to potential resource exhaustion. This is fixed in version 1.18.1.
CVSS Information
N/A
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Ruby SAML 安全漏洞
Vulnerability Description
Ruby SAML是SAML-Toolkits开源的一个 SAML 授权客户端的实现。 Ruby SAML 1.18.0及之前版本存在安全漏洞,该漏洞源于在检查消息大小前验证SAML响应的Base64格式,可能导致资源耗尽。
CVSS Information
N/A
Vulnerability Type
N/A