Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Top tech startup funding news for today, May 8, 2025

Who is Pope Leo XIV, the first American papal craftsman? |Religious News

Student protester Mohsen Mahdawi announces legal defense funds for immigrants | Donald Trump News

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Github reveals new Ruby-Saml vulnerabilities that allow account acquisition attacks
Identity

Github reveals new Ruby-Saml vulnerabilities that allow account acquisition attacks

userBy userMarch 13, 2025No Comments1 Min Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 13, 2025Ravi LakshmananAuthentication/Vulnerability

Ruby-Saml vulnerabilities

The open source Ruby-SAML library discloses two high-strength security flaws that allow malicious actors to bypass Security Assertion Markup Language (SAML) authentication protection.

SAML is an XML-based markup language, an open standard used to exchange authentication and authorization data between parties, enabling features such as single sign-on (SSO). This allows individuals to access multiple sites, services, and apps using a single credential.

The vulnerabilities tracked as CVE-2025-25291 and CVE-2025-25292 have a CVSS score of 8.8 out of 10.0. They affect the next version of the library –

<1.12.4> = 1.13.0, <1.18.0

The drawback of both is that both rexml and nokogiri xml are different ways, with two parsers generating completely different document structures from the same XML input

This parser differentiation allows the attacker to perform signature wrapping attacks, leading to authentication bypass. The vulnerability is addressed in Ruby-SAML versions 1.12.4 and 1.18.0.

Cybersecurity

Microsoft-owned Github, which discovered and reported the flaw in November 2024, said it could be abused by malicious actors to carry out account takeover attacks.

“Attackers who own a single valid signature created with the key used to validate SAML responses or target organizational assertions can use it to construct the SAML assertion itself and log in as any user.”

The Microsoft-owned subsidiary also noted that the issue was summarised in a “cutoff” between hash verification and signature verification, opening the door to exploitation through parser differentiation.

Versions 1.12.4 and 1.18.0 also plug in remote denial of service (DOS) defects when processing compressed SAML responses (CVE-2025-25293, CVSS score: 7.7). Users are advised to update to the latest version to protect against potential threats.

The findings arise almost six months after Gitlab and Ruby-Saml moved to address another important vulnerability (CVE-2024-45409, CVSS score: 10.0).

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWBO orders usyk to defend heavyweight boxing title against Parker | Boxing News
Next Article Bill Gates’ groundbreaking energy excludes European and US climate policy teams after USAID funding hit
user
  • Website

Related Posts

Over 38,000 Freedrain subdomains have been discovered after exploiting SEO to steal crypto wallet seed phrases

May 8, 2025

SONICWALL Patch 3 flaws in SMA 100 devices allow attackers to execute code as root

May 8, 2025

Qilin ransomware ranked best in April 2025 with over 45 data leak disclosures

May 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Top tech startup funding news for today, May 8, 2025

Who is Pope Leo XIV, the first American papal craftsman? |Religious News

Student protester Mohsen Mahdawi announces legal defense funds for immigrants | Donald Trump News

He was appointed as the only finalist for former president of Governor Li Li University in Florida.

Trending Posts

Who is Pope Leo XIV, the first American papal craftsman? |Religious News

May 8, 2025

Student protester Mohsen Mahdawi announces legal defense funds for immigrants | Donald Trump News

May 8, 2025

Man UTD defeated Athletic Club to establish the Europa League Final with Tottenham | Football News

May 8, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Top tech startup funding news for today, May 8, 2025

Health Technology Startup Kouper emerges from $10 million stealth in funding to transform the patient care transition

Did Figma kill Webflow and Framer with the release of the Figma site?

Metaworld Congress 2025: Madrid Takes Center Stage in Digital Innovation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.