OneLogin kayıtları
onelogin üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %90,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-347 Improper Verification of Cryptographic Signature5
- CWE-287 Improper Authentication2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-798 Use of Hard-coded Credentials1
- CWE-91 XML Injection (aka Blind XPath Injection)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2025-25292İstismar yok | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)omniauth · omniauth saml · CWE-347 | Kritik9,3 | — | %65,1 | 12 Mar 2025 |
43Planlayın | CVE-2025-25291Kavram kanıtı | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)omniauth · omniauth saml · CWE-347 | Kritik9,3 | — | %20,6 | 12 Mar 2025 |
42Planlayın | CVE-2024-45409Kavram kanıtı | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectoronelogin · ruby-saml · CWE-347 | Kritik9,8 | — | %10,7 | 10 Eyl 2024 |
40Planlayın | CVE-2017-11427Kavram kanıtı | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalonelogin · pythonsaml · CWE-287 | Kritik9,8 | — | %4,7 | 17 Nis 2019 |
40Planlayın | CVE-2017-11428İstismar yok | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalonelogin · ruby-saml · CWE-287 | Kritik9,8 | — | %2,4 | 17 Nis 2019 |
39İzleyin | CVE-2015-20108İstismar yok | xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not useonelogin · ruby-saml · CWE-77 | Kritik9,8 | — | %1,3 | 27 May 2023 |
37İzleyin | CVE-2025-66567İstismar yok | ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)onelogin · ruby-saml · CWE-347 | Kritik9,3 | — | %0,4 | 9 Ara 2025 |
37İzleyin | CVE-2025-66568İstismar yok | ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validationonelogin · ruby-saml · CWE-347 | Kritik9,3 | — | %0,2 | 9 Ara 2025 |
31İzleyin | CVE-2016-10928İstismar yok | The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.onelogin · onelogin saml sso · CWE-798 | Yüksek7,5 | — | %1,7 | 22 Ağu 2019 |
30İzleyin | CVE-2025-25293İstismar yok | ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responsesomniauth · omniauth saml · CWE-400 | Yüksek7,7 | — | %1,5 | 12 Mar 2025 |
30İzleyin | CVE-2016-5697İstismar yok | Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.onelogin · ruby-saml · CWE-91 | Yüksek7,5 | — | %1,2 | 23 Oca 2017 |
- CVE-2025-2529257Planlayın
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
KritikCVSS 9,3İstismar yokEPSS %65omniauth · omniauth saml12 Mar 2025
- CVE-2025-2529143Planlayın
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
KritikCVSS 9,3Kavram kanıtıEPSS %21omniauth · omniauth saml12 Mar 2025
- CVE-2024-4540942Planlayın
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
KritikCVSS 9,8Kavram kanıtıEPSS %11onelogin · ruby-saml10 Eyl 2024
- CVE-2017-1142740Planlayın
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
KritikCVSS 9,8Kavram kanıtıEPSS %5onelogin · pythonsaml17 Nis 2019
- CVE-2017-1142840Planlayın
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
KritikCVSS 9,8İstismar yokEPSS %2onelogin · ruby-saml17 Nis 2019
- CVE-2015-2010839İzleyin
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not use
KritikCVSS 9,8İstismar yokEPSS %1onelogin · ruby-saml27 May 2023
- CVE-2025-6656737İzleyin
ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
KritikCVSS 9,3İstismar yokEPSS %0onelogin · ruby-saml9 Ara 2025
- CVE-2025-6656837İzleyin
ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validation
KritikCVSS 9,3İstismar yokEPSS %0onelogin · ruby-saml9 Ara 2025
- CVE-2016-1092831İzleyin
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
YüksekCVSS 7,5İstismar yokEPSS %2onelogin · onelogin saml sso22 Ağu 2019
- CVE-2025-2529330İzleyin
ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
YüksekCVSS 7,7İstismar yokEPSS %1omniauth · omniauth saml12 Mar 2025
- CVE-2016-569730İzleyin
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
YüksekCVSS 7,5İstismar yokEPSS %1onelogin · ruby-saml23 Oca 2017