Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Blue Origin cancels second New Glenn launch, will try again on November 12th

Slow Ventures hosts a ‘finishing school’ to help founders learn to be fancy

Blue Origin cancels second New Glenn launch due to weather and cruise ship traffic

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Github reveals new Ruby-Saml vulnerabilities that allow account acquisition attacks
Identity

Github reveals new Ruby-Saml vulnerabilities that allow account acquisition attacks

userBy userMarch 13, 2025No Comments1 Min Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 13, 2025Ravi LakshmananAuthentication/Vulnerability

Ruby-Saml vulnerabilities

The open source Ruby-SAML library discloses two high-strength security flaws that allow malicious actors to bypass Security Assertion Markup Language (SAML) authentication protection.

SAML is an XML-based markup language, an open standard used to exchange authentication and authorization data between parties, enabling features such as single sign-on (SSO). This allows individuals to access multiple sites, services, and apps using a single credential.

The vulnerabilities tracked as CVE-2025-25291 and CVE-2025-25292 have a CVSS score of 8.8 out of 10.0. They affect the next version of the library –

<1.12.4> = 1.13.0, <1.18.0

The drawback of both is that both rexml and nokogiri xml are different ways, with two parsers generating completely different document structures from the same XML input

This parser differentiation allows the attacker to perform signature wrapping attacks, leading to authentication bypass. The vulnerability is addressed in Ruby-SAML versions 1.12.4 and 1.18.0.

Cybersecurity

Microsoft-owned Github, which discovered and reported the flaw in November 2024, said it could be abused by malicious actors to carry out account takeover attacks.

“Attackers who own a single valid signature created with the key used to validate SAML responses or target organizational assertions can use it to construct the SAML assertion itself and log in as any user.”

The Microsoft-owned subsidiary also noted that the issue was summarised in a “cutoff” between hash verification and signature verification, opening the door to exploitation through parser differentiation.

Versions 1.12.4 and 1.18.0 also plug in remote denial of service (DOS) defects when processing compressed SAML responses (CVE-2025-25293, CVSS score: 7.7). Users are advised to update to the latest version to protect against potential threats.

The findings arise almost six months after Gitlab and Ruby-Saml moved to address another important vulnerability (CVE-2024-45409, CVSS score: 10.0).

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWBO orders usyk to defend heavyweight boxing title against Parker | Boxing News
Next Article Bill Gates’ groundbreaking energy excludes European and US climate policy teams after USAID funding hit
user
  • Website

Related Posts

Microsoft discovers ‘whisper leak’ attack that identifies AI chat topics in encrypted traffic

November 8, 2025

Samsung’s zero-click flaw is exploited to deploy LANDFALL Android spyware via WhatsApp

November 7, 2025

From Log4j to IIS, Chinese hackers turn legacy bugs into global spying tools

November 7, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Blue Origin cancels second New Glenn launch, will try again on November 12th

Slow Ventures hosts a ‘finishing school’ to help founders learn to be fancy

Blue Origin cancels second New Glenn launch due to weather and cruise ship traffic

Elon Musk uses Grok to imagine the possibility of love

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.