Записи OmniAuth
8 опубликованных записей вендора omniauth.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-347 Improper Verification of Cryptographic Signature3
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-400 Uncontrolled Resource Consumption1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2025-25292Эксплойта нет | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)omniauth · omniauth saml · CWE-347 | Критическая9,3 | — | 65,1 % | 12 мар. 2025 г. |
43В плане | CVE-2025-25291Proof of concept | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)omniauth · omniauth saml · CWE-347 | Критическая9,3 | — | 20,6 % | 12 мар. 2025 г. |
42В плане | CVE-2024-45409Proof of concept | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectoronelogin · ruby-saml · CWE-347 | Критическая9,8 | — | 10,7 % | 10 сент. 2024 г. |
40В плане | CVE-2017-11430Эксплойта нет | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalomniauth · omniauth saml · CWE-287 | Критическая9,8 | — | 2,4 % | 17 апр. 2019 г. |
39Наблюдать | CVE-2020-36599Эксплойта нет | lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.omniauth · omniauth · CWE-116 | Критическая9,8 | — | 1,1 % | 18 авг. 2022 г. |
35Наблюдать | CVE-2015-9284Эксплойта нет | The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on omniauth · omniauth · CWE-352 | Высокая8,8 | — | 1,6 % | 26 апр. 2019 г. |
31Наблюдать | CVE-2017-18076Эксплойта нет | In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters aomniauth · omniauth | Высокая7,5 | — | 2,1 % | 26 янв. 2018 г. |
30Наблюдать | CVE-2025-25293Эксплойта нет | ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responsesomniauth · omniauth saml · CWE-400 | Высокая7,7 | — | 1,5 % | 12 мар. 2025 г. |
- CVE-2025-2529257В плане
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
КритическаяCVSS 9,3Эксплойта нетEPSS 65 %omniauth · omniauth saml12 мар. 2025 г.
- CVE-2025-2529143В плане
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
КритическаяCVSS 9,3Proof of conceptEPSS 21 %omniauth · omniauth saml12 мар. 2025 г.
- CVE-2024-4540942В плане
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
КритическаяCVSS 9,8Proof of conceptEPSS 11 %onelogin · ruby-saml10 сент. 2024 г.
- CVE-2017-1143040В плане
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %omniauth · omniauth saml17 апр. 2019 г.
- CVE-2020-3659939Наблюдать
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %omniauth · omniauth18 авг. 2022 г.
- CVE-2015-928435Наблюдать
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %omniauth · omniauth26 апр. 2019 г.
- CVE-2017-1807631Наблюдать
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %omniauth · omniauth26 янв. 2018 г.
- CVE-2025-2529330Наблюдать
ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %omniauth · omniauth saml12 мар. 2025 г.