Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

How Brex is catching up to AI by embracing “confusion”

In the US, urban gondolas face uphill battles

Act 2 of Drive Capital – How Columbus Ventures Success After Split

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Github reveals new Ruby-Saml vulnerabilities that allow account acquisition attacks
Identity

Github reveals new Ruby-Saml vulnerabilities that allow account acquisition attacks

userBy userMarch 13, 2025No Comments1 Min Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 13, 2025Ravi LakshmananAuthentication/Vulnerability

Ruby-Saml vulnerabilities

The open source Ruby-SAML library discloses two high-strength security flaws that allow malicious actors to bypass Security Assertion Markup Language (SAML) authentication protection.

SAML is an XML-based markup language, an open standard used to exchange authentication and authorization data between parties, enabling features such as single sign-on (SSO). This allows individuals to access multiple sites, services, and apps using a single credential.

The vulnerabilities tracked as CVE-2025-25291 and CVE-2025-25292 have a CVSS score of 8.8 out of 10.0. They affect the next version of the library –

<1.12.4> = 1.13.0, <1.18.0

The drawback of both is that both rexml and nokogiri xml are different ways, with two parsers generating completely different document structures from the same XML input

This parser differentiation allows the attacker to perform signature wrapping attacks, leading to authentication bypass. The vulnerability is addressed in Ruby-SAML versions 1.12.4 and 1.18.0.

Cybersecurity

Microsoft-owned Github, which discovered and reported the flaw in November 2024, said it could be abused by malicious actors to carry out account takeover attacks.

“Attackers who own a single valid signature created with the key used to validate SAML responses or target organizational assertions can use it to construct the SAML assertion itself and log in as any user.”

The Microsoft-owned subsidiary also noted that the issue was summarised in a “cutoff” between hash verification and signature verification, opening the door to exploitation through parser differentiation.

Versions 1.12.4 and 1.18.0 also plug in remote denial of service (DOS) defects when processing compressed SAML responses (CVE-2025-25293, CVSS score: 7.7). Users are advised to update to the latest version to protect against potential threats.

The findings arise almost six months after Gitlab and Ruby-Saml moved to address another important vulnerability (CVE-2024-45409, CVSS score: 10.0).

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWBO orders usyk to defend heavyweight boxing title against Parker | Boxing News
Next Article Bill Gates’ groundbreaking energy excludes European and US climate policy teams after USAID funding hit
user
  • Website

Related Posts

Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

July 5, 2025

The exposed JDWP interface leads to crypto mining, and Hpingbot targets DDO’s SSH

July 5, 2025

TwinH: A New Frontier in the Pursuit of Immortality?

July 4, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

How Brex is catching up to AI by embracing “confusion”

In the US, urban gondolas face uphill battles

Act 2 of Drive Capital – How Columbus Ventures Success After Split

Don’t ask the blue ski toll ruble, it’s a toll for you

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.