Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5868
HistoryMar 01, 2018 - 5:55 a.m.

Authorization Bypass

2018-03-0105:55:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.011 Low

EPSS

Percentile

84.2%

OmniAuth-saml is vulnerable to authentication bypass. The application uses a vulnerable version of ruby-saml , meaning it does not properly parse comments in certain XML nodes, causing text after a comment being lost before signing the SAML Message. This allows a malicious user to modify a SAML message without invalidating the cryptographic signature and bypass authentication for the SAML provider.

CPENameOperatorVersion
omniauth-samlle1.9.0

0.011 Low

EPSS

Percentile

84.2%