{"id":"GHSA-cvp8-5r8g-fhvq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-cvp8-5r8g-fhvq","summary":"omniauth-saml vulnerable to Improper Verification of Cryptographic Signature","details":"ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 \nAs a result, omniauth-saml created a [new release](https://github.com/omniauth/omniauth-saml/releases) by upgrading ruby-saml to the patched versions v1.17. \n","published":"2024-09-11T21:08:26Z","modified":"2026-08-07T08:11:59.192768697Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"omniauth-saml","fixedVersion":"2.1.2"},{"ecosystem":"RubyGems","name":"omniauth-saml","fixedVersion":"1.10.5"},{"ecosystem":"RubyGems","name":"omniauth-saml","fixedVersion":"2.2.1"}],"fix":{"url":"https://github.com/omniauth/omniauth-saml/commit/4274e9d57e65f2dcaae4aa3b2accf831494f2ddd","label":"omniauth/omniauth-saml@4274e9d"},"references":[{"type":"WEB","url":"https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-cvp8-5r8g-fhvq"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/commit/4274e9d57e65f2dcaae4aa3b2accf831494f2ddd"},{"type":"WEB","url":"https://github.com/omniauth/omniauth-saml/commit/6c681fd082ab3daf271821897a40ab3417382e29"},{"type":"PACKAGE","url":"https://github.com/omniauth/omniauth-saml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-saml/GHSA-cvp8-5r8g-fhvq.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T08:11:59.192768697Z"}}