Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5862
HistoryFeb 28, 2018 - 5:55 a.m.

Authentication Bypass

2018-02-2805:55:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

EPSS

0.01

Percentile

83.6%

ruby-saml is vulnerable to authentication bypass. The application does not properly parse comments in certain XML nodes, causing text after a comment being lost before signing the SAML Message. This allows a malicious user to modify a SAML message without invalidating the cryptographic signature and bypass authentication for the SAML provider.

EPSS

0.01

Percentile

83.6%