SB2024091807 - GitLab update for omniauth-saml and ruby-saml
Published: September 18, 2024 Updated: October 11, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper verification of cryptographic signature (CVE-ID: CVE-2024-45409)
The vulnerability allows a remote attacker to bypass SAML authentication.
The vulnerability exists due to the library does not properly verify the signature of the SAML Response. A remote non-authenticated attacker with access to any signed SAML document (by the IdP) can forge a SAML Response/Assertion with arbitrary contents, bypass authentication process and login under an arbitrary account within the application.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected application.
Remediation
Install update from vendor's website.