USN-7309-1
Dashboard / Vulnerabilities / USN-7309-1
USN-7309-1
Summary: Ruby SAML vulnerabilities
Details: It was discovered that Ruby SAML did not properly validate SAML responses. An unauthenticated attacker could use this vulnerability to log in as an abitrary user. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-5697) It was discovered that Ruby SAML incorrectly utilized the results of XML DOM traversal and canonicalization APIs. An unauthenticated attacker could use this vulnerability to log in as an abitrary user. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-11428) It was discovered that Ruby SAML did not properly verify the signature of the SAML Response, allowing multiple elements with the same ID. An unauthenticated attacker could use this vulnerability to log in as an abitrary user. (CVE-2024-45409)
References: https://ubuntu.com/security/notices/USN-7309-1, https://ubuntu.com/security/CVE-2016-5697, https://ubuntu.com/security/CVE-2017-11428, https://ubuntu.com/security/CVE-2024-45409
Affected packages
Package
Name: ruby-saml
Purl: pkg:deb/ubuntu/ruby-saml?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
