PT-2025-11129 · Ruby-Saml+3 · Ruby-Saml+3

Pitbulk

·

Published

2025-03-12

·

Updated

2025-12-09

·

CVE-2025-25292

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ruby-saml versions prior to 1.12.4 and 1.18.0
Description An authentication bypass vulnerability was found in ruby-saml due to a parser differential. ReXML and Nokogiri parse XML differently, generating entirely different document structures from the same XML input. This allows an attacker to execute a Signature Wrapping attack, which may lead to authentication bypass.
Recommendations To resolve the issue, update to version 1.12.4 or 1.18.0, as these versions contain a patch for the vulnerability. For versions prior to 1.12.4 and 1.18.0, consider disabling the ReXML and Nokogiri parsers until a patch is applied. Restrict access to the SAML authentication endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

BDU:2025-02782
BIT-GITLAB-2025-25292
CVE-2025-25292
DLA-4115-1
GHSA-754F-8GM6-C4R2
GHSA-HW46-3HMR-X9XV
USN-7409-1

Affected Products

Debian
Linuxmint
Ubuntu
Ruby-Saml