UbuntuUpdates.org

Package "ruby-saml"

Name: ruby-saml

Description:

SAML toolkit for Ruby on Rails

Latest version: 1.11.0-1ubuntu0.1
Release: focal (20.04)
Level: updates
Repository: universe
Homepage: https://github.com/onelogin/ruby-saml

Links


Download "ruby-saml"


Other versions of "ruby-saml" in Focal

Repository Area Version
base universe 1.11.0-1
security universe 1.11.0-1ubuntu0.1

Changelog

Version: 1.11.0-1ubuntu0.1 2025-02-28 06:06:55 UTC

  ruby-saml (1.11.0-1ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: SAML signature wrapping authentication bypass
    - debian/patches/CVE-2024-45409.patch: use correct XPaths, resolve
      to correct elements, and block references that resolve to
      multiple nodes. Changes made to lib/xml_security.rb
    - CVE-2024-45409

 -- Elise Hlady <email address hidden> Thu, 23 Jan 2025 14:06:01 -0800

CVE-2024-45409 The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify



About   -   Send Feedback to @ubuntu_updates