VDB

CVE-2025-25291

CVE-2025-25291 PUBLISHED

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differently; the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack. This issue may lead to authentication bypass. Versions 1.12.4 and 1.18.0 fix the issue.

EPSS 20.84% · 95.7th percentile

Risk Scores

EPSS Score
20.84%
95.7th percentile

Affected Products

VendorProductVersions
Bitnamigitlab0
Bitnamigitlab0

Timeline

  • Mar 12, 2025 CVE Published
  • Mar 13, 2025 EPSS Score
  • Apr 9, 2025 EPSS Score
  • Apr 15, 2025 EPSS Score
  • May 6, 2025 EPSS Score
  • May 20, 2025 EPSS Score
  • Jun 16, 2025 EPSS Score
  • Jul 12, 2025 EPSS Score
  • Jul 13, 2025 EPSS Score
  • Aug 2, 2025 EPSS Score
  • Aug 9, 2025 EPSS Score
  • Aug 17, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›