漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Vulnerability Description
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for CVE-2025-25292. ReXML and Nokogiri parse XML differently, generating entirely different document structures from the same input. This allows an attacker to execute a Signature Wrapping attack. This issue is fixed in version 1.18.0.
CVSS Information
N/A
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
OneLogin ruby-saml 数据伪造问题漏洞
Vulnerability Description
Onelogin OneLogin ruby-saml是美国Onelogin公司的一款基于Ruby的、用于单点登录(SSO)服务的SAML(安全断言标记语言)库。 OneLogin ruby-saml 1.12.4及之前版本存在数据伪造问题漏洞,该漏洞源于XML解析差异,可能导致签名包装攻击和认证绕过。
CVSS Information
N/A
Vulnerability Type
N/A