Ubuntu Security Update USN-7409-1: RubySAML vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,817
Reaction score
74
Credits
-1,257
It was discovered that ruby-saml did not correctly handle XML parsing. An attacker could possibly use this issue to perform a signature wrapping attack and bypass authentication. (CVE-2025-25291 and CVE-2025-25292) It was discovered that ruby-saml did not correctly handle decompressing SAML responses. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-25293)

Continue reading...
 


Follow Linux.org

Members online


Top