CVE-2025-66567 is an authentication bypass vulnerability affecting ruby-saml versions up to and including 1.12.4, stemming from an incomplete fix for a prior CVE. It allows attackers to perform a Signature Wrapping attack due to differing XML parsing behaviors between REXML and Nokogiri, impacting the client-side implementation of SAML authorization. This critical vulnerability, with a CVSS score of 9.1, has a low attack complexity and can lead to high confidentiality and integrity impacts. While there is no known exploit code or active exploitation, the vulnerability has garnered significant community discussion and media coverage, indicating a high level of concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.18.0CPE matchmatch criteria | cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.