File tree Expand file tree Collapse file tree 2 files changed +28
-0
lines changed Expand file tree Collapse file tree 2 files changed +28
-0
lines changed Original file line number Diff line number Diff line change @@ -44,6 +44,7 @@ description: |+
4444 * protobuf-kotlin-lite (3.25.5, 4.27.5, 4.28.2)
4545 * com-protobuf [JRuby gem only] (3.25.5, 4.27.5, 4.28.2)
4646
47+ cvss_v3 : 7.5
4748cvss_v4 : 8.7
4849patched_versions :
4950 - " ~> 3.25.5"
Original file line number Diff line number Diff line change 1+ ---
2+ gem : omniauth-saml
3+ ghsa : cvp8-5r8g-fhvq
4+ url : https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2
5+ title : omniauth-saml vulnerable to Improper Verification of Cryptographic Signature
6+ date : 2024-09-11
7+ description : |
8+ ruby-saml, the dependent SAML gem of omniauth-saml has a signature
9+ wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see
10+ https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2
11+
12+ As a result, omniauth-saml created a
13+ [new release](https://github.com/omniauth/omniauth-saml/releases)
14+ by upgrading ruby-saml to the patched versions v1.17.
15+ cvss_v3 : 10.0
16+ patched_versions :
17+ - " ~> 1.10.5"
18+ - " ~> 2.1.2"
19+ - " >= 2.2.1"
20+ related :
21+ url :
22+ - https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2
23+ - https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-cvp8-5r8g-fhvq
24+ - https://github.com/omniauth/omniauth-saml/commit/4274e9d57e65f2dcaae4aa3b2accf831494f2ddd
25+ - https://github.com/omniauth/omniauth-saml/commit/6c681fd082ab3daf271821897a40ab3417382e29
26+ - https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-saml/GHSA-cvp8-5r8g-fhvq.yml
27+ - https://github.com/advisories/GHSA-cvp8-5r8g-fhvq
You can’t perform that action at this time.
0 commit comments