<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T08:04:23.159560+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2017-11428</id>
    <title>CVE-2017-11428 — Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal</title>
    <updated>2026-10-09T08:04:23.203167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OneLogin Ruby-SAML</p>
<p>OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2017-11428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-7309-1</id>
    <title>USN-7309-1 — Ruby SAML vulnerabilities</title>
    <updated>2026-10-09T08:04:23.203286+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ruby-saml, Ubuntu:Pro:18.04:LTS: ruby-saml, Ubuntu:20.04:LTS: ruby-saml, Ubuntu:22.04:LTS: ruby-saml, Ubuntu:24.04:LTS: ruby-saml</p>
<p>It was discovered that Ruby SAML did not properly validate SAML responses.
An unauthenticated attacker could use this vulnerability to log in as an 
abitrary user. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-5697)</p>
<p>It was discovered that Ruby SAML incorrectly utilized the results of XML
DOM traversal and canonicalization APIs. An unauthenticated attacker could
use this vulnerability to log in as an abitrary user. This issue only 
affected Ubuntu 16.04 LTS. (CVE-2017-11428)</p>
<p>It was discovered that Ruby SAML did not properly verify the signature of
the SAML Response, allowing multiple elements with the same ID. An 
unauthenticated attacker could use this vulnerability to log in as an 
abitrary user. (CVE-2024-45409)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-7309-1"/>
  </entry>
</feed>
