PT-2017-8747 · Ruby+2 · Ruby-Saml+2

Alvaro Hoyos

·

Published

2017-01-23

·

Updated

2025-02-28

·

CVE-2016-5697

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ruby-saml versions prior to 1.3.0
Description The issue allows attackers to perform XML signature wrapping attacks. This occurs in a specific scenario where a signature references two elements simultaneously, one of which is inside an encrypted assertion, bypassing the scheme validator process.
Recommendations For ruby-saml versions prior to 1.3.0, update to version 1.3.0, which implements extra validations to mitigate this kind of attack.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2016-5697
GHSA-36P7-XJW8-H6F2
USN-7309-1

Affected Products

Linuxmint
Ubuntu
Ruby-Saml