« Volver al listado

Onelogin

Onelogin Ruby-saml: vulnerabilidades y CVE

Onelogin Ruby-saml tiene 10 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses2
Críticas7
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-66568Crítica (9.3)0.23%—9 dic 2025
The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for…
CVE-2025-66567Crítica (9.3)0.39%—9 dic 2025
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentication bypass vulnerability due to an incomplete fix for…
CVE-2025-54572Media (6.9)0.40%—30 jul 2025
The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability exists in ruby-saml even with the message_max_bytesize setting…
CVE-2025-25293Alta (7.7)1.5%—12 mar 2025
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses.…
CVE-2025-25292Crítica (9.3)65%—12 mar 2025
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential.…
CVE-2025-25291Crítica (9.3)21%—12 mar 2025
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential.…
CVE-2024-45409Crítica (9.8)11%—10 sept 2024
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with…
CVE-2015-20108Crítica (9.8)1.3%—27 may 2023
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
CVE-2017-11428Crítica (9.8)2.4%—17 abr 2019
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the…
CVE-2016-5697Alta (7.5)1.2%—23 ene 2017
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Onelogin