Skip to content
Noroxi

OmniAuth records

8 published records for vendor omniauth.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

8 records
  • Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)

    CriticalCVSS 9.3No exploitEPSS 65%

    omniauth · omniauth samlMar 12, 2025

  • ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)

    CriticalCVSS 9.3Proof of conceptEPSS 21%

    omniauth · omniauth samlMar 12, 2025

  • The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    onelogin · ruby-samlSep 10, 2024

  • Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal

    CriticalCVSS 9.8No exploitEPSS 2%

    omniauth · omniauth samlApr 17, 2019

  • lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.

    CriticalCVSS 9.8No exploitEPSS 1%

    omniauth · omniauthAug 18, 2022

  • CVE-2015-9284
    35Monitor

    The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on

    HighCVSS 8.8No exploitEPSS 2%

    omniauth · omniauthApr 26, 2019

  • In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters a

    HighCVSS 7.5No exploitEPSS 2%

    omniauth · omniauthJan 26, 2018

  • ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses

    HighCVSS 7.7No exploitEPSS 1%

    omniauth · omniauth samlMar 12, 2025