Improper verification of cryptographic signature in SAML SSO for Ruby - CVE-2024-45409
Published: September 18, 2024 / Updated: October 11, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass SAML authentication.
The vulnerability exists due to the library does not properly verify the signature of the SAML Response. A remote non-authenticated attacker with access to any signed SAML document (by the IdP) can forge a SAML Response/Assertion with arbitrary contents, bypass authentication process and login under an arbitrary account within the application.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected application.
Affected software
omniauth-saml
Debian Linux
GitLab Enterprise Edition
Gitlab Community Edition
ruby-saml (Debian package)
How to mitigate CVE-2024-45409
omniauth-saml - update to 2.2.1
GitLab Enterprise Edition - addressed in versions 16.11.10, 17.0.8, 17.1.8, 17.2.7, 17.3.3
Gitlab Community Edition - addressed in versions 16.11.10, 17.0.8, 17.1.8, 17.2.7, 17.3.3
ruby-saml (Debian package) - update to 1.13.0-1+deb12u1