OmniAuth kayıtları
omniauth üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-347 Improper Verification of Cryptographic Signature3
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2025-25292İstismar yok | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)omniauth · omniauth saml · CWE-347 | Kritik9,3 | — | %65,1 | 12 Mar 2025 |
43Planlayın | CVE-2025-25291Kavram kanıtı | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)omniauth · omniauth saml · CWE-347 | Kritik9,3 | — | %20,6 | 12 Mar 2025 |
42Planlayın | CVE-2024-45409Kavram kanıtı | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectoronelogin · ruby-saml · CWE-347 | Kritik9,8 | — | %10,7 | 10 Eyl 2024 |
40Planlayın | CVE-2017-11430İstismar yok | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalomniauth · omniauth saml · CWE-287 | Kritik9,8 | — | %2,4 | 17 Nis 2019 |
39İzleyin | CVE-2020-36599İstismar yok | lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.omniauth · omniauth · CWE-116 | Kritik9,8 | — | %1,1 | 18 Ağu 2022 |
35İzleyin | CVE-2015-9284İstismar yok | The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on omniauth · omniauth · CWE-352 | Yüksek8,8 | — | %1,6 | 26 Nis 2019 |
31İzleyin | CVE-2017-18076İstismar yok | In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters aomniauth · omniauth | Yüksek7,5 | — | %2,1 | 26 Oca 2018 |
30İzleyin | CVE-2025-25293İstismar yok | ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responsesomniauth · omniauth saml · CWE-400 | Yüksek7,7 | — | %1,5 | 12 Mar 2025 |
- CVE-2025-2529257Planlayın
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
KritikCVSS 9,3İstismar yokEPSS %65omniauth · omniauth saml12 Mar 2025
- CVE-2025-2529143Planlayın
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
KritikCVSS 9,3Kavram kanıtıEPSS %21omniauth · omniauth saml12 Mar 2025
- CVE-2024-4540942Planlayın
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
KritikCVSS 9,8Kavram kanıtıEPSS %11onelogin · ruby-saml10 Eyl 2024
- CVE-2017-1143040Planlayın
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
KritikCVSS 9,8İstismar yokEPSS %2omniauth · omniauth saml17 Nis 2019
- CVE-2020-3659939İzleyin
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
KritikCVSS 9,8İstismar yokEPSS %1omniauth · omniauth18 Ağu 2022
- CVE-2015-928435İzleyin
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on
YüksekCVSS 8,8İstismar yokEPSS %2omniauth · omniauth26 Nis 2019
- CVE-2017-1807631İzleyin
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters a
YüksekCVSS 7,5İstismar yokEPSS %2omniauth · omniauth26 Oca 2018
- CVE-2025-2529330İzleyin
ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
YüksekCVSS 7,7İstismar yokEPSS %1omniauth · omniauth saml12 Mar 2025