Known vulnerabilities in SAML SSO for Ruby
Vendor:
SAML-Toolkits
Software:
SAML SSO for Ruby
Software CPE:
cpe:2.3:a:saml-toolkits:ruby-saml:*:*:*:*:*:*:*:*
Website:
https://github.com/SAML-Toolkits
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.18.1
1.12.4
1.18.0
1.17.0
1.16.0
1.15.0
1.14.0
1.13.0
1.12.3
1.12.2
1.12.1
1.12.0
1.11.0
1.10.2
1.10.1
1.10.0
1.9.0
1.8.0
1.7.2
1.7.1
1.7.0
1.6.2
1.6.1
1.6.0
1.5.0
1.4.3
1.4.2
1.4.1
1.4.0
1.3.1
1.3.0
1.2.0
1.1.2
1.1.1
1.1.0
1.0.0
0.9.3
0.9.2
0.9.1
0.9
0.8.3
0.8.2
0.8.1
0.8.0
0.7.3
0.7.1
0.7.0
0.6.0
0.5.3
0.5.2
0.5.1
0.5.0
0.4.7
0.4.6
0.4.5
0.4.4
0.4.3
0.4.2
0.4.1
0.4.0
0.3.4
0.3.3
0.3.2
0.3.1
0.3.0
0.2.3
0.2.2
0.2.1
0.2.0
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU119405 - Improper Verification of Cryptographic Signature CVE-2025-66567 |
CWE-347 | High | 1.18.0 | 09.12.2025 |
SB2025120933 SB2026021820 |
||
| #VU119404 - Improper Verification of Cryptographic Signature CVE-2025-66568 |
CWE-347 | High | 1.18.0 | 09.12.2025 |
SB2025120933 SB2026021820 |
||
| #VU105982 - Resource exhaustion CVE-2025-25293 |
CWE-400 | Medium | 1.12.4, 1.18.0 | 24.03.2025 |
SB2025031314 SB20250402144 |
||
| #VU105688 - Improper Verification of Cryptographic Signature CVE-2025-25292 |
CWE-347 | High | 1.12.4, 1.18.0 | 13.03.2025 |
SB2025031314 SB2025031316 SB20250402144 and 1 more |
||
| #VU105687 - Improper Verification of Cryptographic Signature CVE-2025-25291 |
CWE-347 | High | 1.12.4, 1.18.0 | 13.03.2025 |
SB2025031314 SB2025031316 SB20250402144 |
||
| #VU97454 - Improper Verification of Cryptographic Signature CVE-2024-45409 |
CWE-347 | High | 1.12.3, 1.17.0 | 18.09.2024 |
SB2024091805 SB2024091806 SB2024091807 and 1 more |