OmniAuth records
8 published records for vendor omniauth.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-347 Improper Verification of Cryptographic Signature3
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2025-25292No exploit | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)omniauth · omniauth saml · CWE-347 | Critical9.3 | — | 65.1% | Mar 12, 2025 |
43Plan | CVE-2025-25291Proof of concept | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)omniauth · omniauth saml · CWE-347 | Critical9.3 | — | 20.6% | Mar 12, 2025 |
42Plan | CVE-2024-45409Proof of concept | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectoronelogin · ruby-saml · CWE-347 | Critical9.8 | — | 10.7% | Sep 10, 2024 |
40Plan | CVE-2017-11430No exploit | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalomniauth · omniauth saml · CWE-287 | Critical9.8 | — | 2.4% | Apr 17, 2019 |
39Monitor | CVE-2020-36599No exploit | lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.omniauth · omniauth · CWE-116 | Critical9.8 | — | 1.1% | Aug 18, 2022 |
35Monitor | CVE-2015-9284No exploit | The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on omniauth · omniauth · CWE-352 | High8.8 | — | 1.6% | Apr 26, 2019 |
31Monitor | CVE-2017-18076No exploit | In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters aomniauth · omniauth | High7.5 | — | 2.1% | Jan 26, 2018 |
30Monitor | CVE-2025-25293No exploit | ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responsesomniauth · omniauth saml · CWE-400 | High7.7 | — | 1.5% | Mar 12, 2025 |
- CVE-2025-2529257Plan
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
CriticalCVSS 9.3No exploitEPSS 65%omniauth · omniauth samlMar 12, 2025
- CVE-2025-2529143Plan
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
CriticalCVSS 9.3Proof of conceptEPSS 21%omniauth · omniauth samlMar 12, 2025
- CVE-2024-4540942Plan
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
CriticalCVSS 9.8Proof of conceptEPSS 11%onelogin · ruby-samlSep 10, 2024
- CVE-2017-1143040Plan
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
CriticalCVSS 9.8No exploitEPSS 2%omniauth · omniauth samlApr 17, 2019
- CVE-2020-3659939Monitor
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
CriticalCVSS 9.8No exploitEPSS 1%omniauth · omniauthAug 18, 2022
- CVE-2015-928435Monitor
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on
HighCVSS 8.8No exploitEPSS 2%omniauth · omniauthApr 26, 2019
- CVE-2017-1807631Monitor
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters a
HighCVSS 7.5No exploitEPSS 2%omniauth · omniauthJan 26, 2018
- CVE-2025-2529330Monitor
ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
HighCVSS 7.7No exploitEPSS 1%omniauth · omniauth samlMar 12, 2025