Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Most Americans disapprove of Trump’s treatment of universities, a new poll finds

Beyond Vulnerability Management – Can You CVE What I CVE?

The UK and Norway accelerate clean energy opportunities

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Github reveals new Ruby-Saml vulnerabilities that allow account acquisition attacks
Identity

Github reveals new Ruby-Saml vulnerabilities that allow account acquisition attacks

userBy userMarch 13, 2025No Comments1 Min Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 13, 2025Ravi LakshmananAuthentication/Vulnerability

Ruby-Saml vulnerabilities

The open source Ruby-SAML library discloses two high-strength security flaws that allow malicious actors to bypass Security Assertion Markup Language (SAML) authentication protection.

SAML is an XML-based markup language, an open standard used to exchange authentication and authorization data between parties, enabling features such as single sign-on (SSO). This allows individuals to access multiple sites, services, and apps using a single credential.

The vulnerabilities tracked as CVE-2025-25291 and CVE-2025-25292 have a CVSS score of 8.8 out of 10.0. They affect the next version of the library –

<1.12.4> = 1.13.0, <1.18.0

The drawback of both is that both rexml and nokogiri xml are different ways, with two parsers generating completely different document structures from the same XML input

This parser differentiation allows the attacker to perform signature wrapping attacks, leading to authentication bypass. The vulnerability is addressed in Ruby-SAML versions 1.12.4 and 1.18.0.

Cybersecurity

Microsoft-owned Github, which discovered and reported the flaw in November 2024, said it could be abused by malicious actors to carry out account takeover attacks.

“Attackers who own a single valid signature created with the key used to validate SAML responses or target organizational assertions can use it to construct the SAML assertion itself and log in as any user.”

The Microsoft-owned subsidiary also noted that the issue was summarised in a “cutoff” between hash verification and signature verification, opening the door to exploitation through parser differentiation.

Versions 1.12.4 and 1.18.0 also plug in remote denial of service (DOS) defects when processing compressed SAML responses (CVE-2025-25293, CVSS score: 7.7). Users are advised to update to the latest version to protect against potential threats.

The findings arise almost six months after Gitlab and Ruby-Saml moved to address another important vulnerability (CVE-2024-45409, CVSS score: 10.0).

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWBO orders usyk to defend heavyweight boxing title against Parker | Boxing News
Next Article Bill Gates’ groundbreaking energy excludes European and US climate policy teams after USAID funding hit
user
  • Website

Related Posts

Beyond Vulnerability Management – Can You CVE What I CVE?

May 9, 2025

Google deploys AI protection on your device to detect Chrome and Android scams

May 9, 2025

Chinese hackers exploit SAP RCE Flaw CVE-2025-31324 to deploy Golang-based SuperShell

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Most Americans disapprove of Trump’s treatment of universities, a new poll finds

Beyond Vulnerability Management – Can You CVE What I CVE?

The UK and Norway accelerate clean energy opportunities

Omoda and Jaecoo will appoint Strata as a UK launch brand experience agency

Trending Posts

Timberwolves beat Curryless Warriors evenly in Game 2 | Basketball News

May 9, 2025

The Vatican’s troubling finances: Can Pope Leo XIV clean it? |Religious News

May 9, 2025

“Sky Missile”: Panic in Indian Frontier City with War Clouds | India and Pakistan’s Tension News

May 9, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

New dedicated blockchain T-Rex raises $17 million to convert the attention layer of Web3

Top tech startup funding news for today, May 8, 2025

Health Technology Startup Kouper emerges from $10 million stealth in funding to transform the patient care transition

Did Figma kill Webflow and Framer with the release of the Figma site?

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.