PT-2025-11129 · Ruby-Saml+3 · Ruby-Saml+3

·

CVE-2025-25292

·

Published

2025-03-12

·

Updated

2025-12-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ruby-saml versions prior to 1.12.4 and 1.18.0
Description An authentication bypass vulnerability was found in ruby-saml due to a parser differential. ReXML and Nokogiri parse XML differently, generating entirely different document structures from the same XML input. This allows an attacker to execute a Signature Wrapping attack, which may lead to authentication bypass.
Recommendations To resolve the issue, update to version 1.12.4 or 1.18.0, as these versions contain a patch for the vulnerability. For versions prior to 1.12.4 and 1.18.0, consider disabling the ReXML and Nokogiri parsers until a patch is applied. Restrict access to the SAML authentication endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02782
BIT-GITLAB-2025-25292
CVE-2025-25292
DLA-4115-1
GHSA-754F-8GM6-C4R2
GHSA-HW46-3HMR-X9XV
USN-7409-1

Affected Products

Debian
Linuxmint
Ubuntu
Ruby-Saml