CRITICAL🇵🇱 Wersja polska

CVE-2025-66568

CVSS 9.3v4.0pub. 2025-12-09upd. 2025-12-10

The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypass through the libxml2 canonicalization process used by Nokogiri for document transformation, which allows an attacker to execute a Signature Wrapping attack. When libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty string rather than a canonicalized node. ruby-saml then proceeds to compute the DigestValue over this empty string, treating it as if canonicalization succeeded. This issue is fixed in version 1.18.0.

🤖 AI Analysis
How it works

The vulnerability results from improper error handling in the XML canonicalization process performed by the libxml2 library (via Nokogiri). When libxml2 processes malformed XML input, it may return an empty string instead of a properly canonicalized node instead of raising an error. The ruby-saml library then continues to calculate the DigestValue for this empty string, treating the operation as successful. Such an error enables an attacker to construct a specially crafted SAML response (Signature Wrapping attack), in which the digital signature is verified for different content than what is actually processed by the application.

Impact

An attacker can completely bypass the SAML-based authentication mechanism and impersonate any user, including an administrator, gaining unauthorized access to applications protected by ruby-saml.

Mitigation & patch

Update the ruby-saml library to version 1.18.0, in which the issue has been fixed. The patch is available in the SAML-Toolkits/ruby-saml GitHub repository.

Who is affected

The ruby-saml library (OneLogin) in versions up to and including 1.12.4.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Onelogin Ruby Saml

    APP
    Onelogin
    < 1.18.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-66567CRITICAL9.3PL ✓same product

Auth Bypass w ruby-saml przez atak Signature Wrapping (CVE-2025-66567)

CVE-2025-25291CRITICAL9.3PL ✓same product

Authentication bypass w ruby-saml poprzez Signature Wrapping (SAML SSO)

CVE-2025-25292CRITICAL9.3PL ✓same product

Pominięcie uwierzytelnienia SAML SSO przez atak Signature Wrapping w ruby-saml

CVE-2024-45409CRITICAL10.0PL ✓same product

Ruby-SAML: pominięcie weryfikacji podpisu odpowiedzi SAML — Auth Bypass

CVE-2015-20108CRITICAL9.8PL ✓same product

XPath injection i RCE w bibliotece ruby-saml (przed wersją 1.0.0)