CVE-2024-45409 is a critical authentication bypass vulnerability in the Ruby SAML library, affecting versions up to 12.2 and from 1.13.0 to 1.16.0, including various GitLab and OmniAuth SAML integrations. An unauthenticated attacker can forge SAML Responses/Assertions with arbitrary content by leveraging any signed SAML document from an Identity Provider, allowing them to log in as any user. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, the vulnerability has a high EPSS score, indicating a significant likelihood of exploitation, and public exploit templates are available for Nuclei. Community discussion and media coverage are extensive, highlighting its severity and the urgency for patching to versions 1.17.0 or 1.12.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.3CPE matchmatch criteria | cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* | ||
>= 1.13.0, < 1.17.0CPE matchmatch criteria | cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* | ||
<= 1.10.3CPE matchmatch criteria | cpe:2.3:a:omniauth:omniauth_saml:*:*:*:*:*:ruby:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:omniauth:omniauth_saml:2.0.0:*:*:*:*:ruby:*:* | ||
2.1.0CPE matchmatch criteria | cpe:2.3:a:omniauth:omniauth_saml:2.1.0:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.