​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-262q-gvxw-gjj6

Published

Last updated

https://images.chainguard.dev/security/CGA-262q-gvxw-gjj6
Package

gitlab-rails-ee-fips-17.1

Latest Update
Fixed
Fixed Version

17.1.8-r0

Aliases
  • GHSA-cvp8-5r8g-fhvq

Severity

10.0

Critical

CVSS V3

Summary

omniauth-saml vulnerable to Improper Verification of Cryptographic Signature

Description

ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images