VDB
BDU%3A2025-02818
BDU%3A2025-02818
PUBLISHED
CVSS 9.399999618530273 CRITICAL
Уязвимость протокола единого входа SAML SSO библиотеки Ruby SAML и программной платформы на базе git для совместной работы над кодом GitLab CE/EE, позволяющая нарушителю обойти аутентификацию
Risk Scores
CVSS 2.0
9.399999618530273
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Ruby Team, GitLab Inc. | Debian GNU/Linux, Ruby SAML, Omniauth SAML, Gitlab |
Timeline
- Mar 17, 2025 CVE Published
References
- https://about.gitlab.com/releases/2025/03/12/patch-release-gitlab-17-9-2-released url
- https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials url
- https://github.com/SAML-Toolkits/ruby-saml/commit/e76c5b36bac40aedbf1ba7ffaaf495be63328cd9 url
- https://github.com/SAML-Toolkits/ruby-saml/commit/e9c1cdbd0f9afa467b585de279db0cbd0fb8ae97 url
- https://github.com/SAML-Toolkits/ruby-saml/releases/tag/v1.12.4 url
- https://github.com/SAML-Toolkits/ruby-saml/releases/tag/v1.18.0 url
- https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-754f-8gm6-c4r2 url
- https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-hw46-3hmr-x9xv url
- https://security-tracker.debian.org/tracker/CVE-2025-25291 url
- https://about.gitlab.com/releases/2025/03/12/patch-release-gitlab-17-9-2-released/ advisory