<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 03:13:42 +0000</lastBuildDate>
    <item>
      <title>CVE-2017-11428 — Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2017-11428</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OneLogin Ruby-SAML&lt;/p&gt;
&lt;p&gt;OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OneLogin Ruby-SAML&lt;/p&gt;
&lt;p&gt;OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2017-11428</guid>
    </item>
    <item>
      <title>USN-7309-1 — Ruby SAML vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-7309-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby-saml, Ubuntu:Pro:18.04:LTS: ruby-saml, Ubuntu:20.04:LTS: ruby-saml, Ubuntu:22.04:LTS: ruby-saml, Ubuntu:24.04:LTS: ruby-saml&lt;/p&gt;
&lt;p&gt;It was discovered that Ruby SAML did not properly validate SAML responses.
An unauthenticated attacker could use this vulnerability to log in as an 
abitrary user. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-5697)&lt;/p&gt;
&lt;p&gt;It was discovered that Ruby SAML incorrectly utilized the results of XML
DOM traversal and canonicalization APIs. An unauthenticated attacker could
use this vulnerability to log in as an abitrary user. This issue only 
affected Ubuntu 16.04 LTS. (CVE-2017-11428)&lt;/p&gt;
&lt;p&gt;It was discovered that Ruby SAML did not properly verify the signature of
the SAML Response, allowing multiple elements with the same ID. An 
unauthenticated attacker could use this vulnerability to log in as an 
abitrary user. (CVE-2024-45409)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ruby-saml, Ubuntu:Pro:18.04:LTS: ruby-saml, Ubuntu:20.04:LTS: ruby-saml, Ubuntu:22.04:LTS: ruby-saml, Ubuntu:24.04:LTS: ruby-saml&lt;/p&gt;
&lt;p&gt;It was discovered that Ruby SAML did not properly validate SAML responses.
An unauthenticated attacker could use this vulnerability to log in as an 
abitrary user. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-5697)&lt;/p&gt;
&lt;p&gt;It was discovered that Ruby SAML incorrectly utilized the results of XML
DOM traversal and canonicalization APIs. An unauthenticated attacker could
use this vulnerability to log in as an abitrary user. This issue only 
affected Ubuntu 16.04 LTS. (CVE-2017-11428)&lt;/p&gt;
&lt;p&gt;It was discovered that Ruby SAML did not properly verify the signature of
the SAML Response, allowing multiple elements with the same ID. An 
unauthenticated attacker could use this vulnerability to log in as an 
abitrary user. (CVE-2024-45409)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-7309-1</guid>
    </item>
  </channel>
</rss>
