ruby-saml, the dependent SAML gem of omniauth-saml has a signature wrapping vulnerability in <= v1.12.0 and v1.13.0 to v1.16.0 , see https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-jw9c-mfg7-9rx2 As a result, omniauth-saml created a new release by upgrading ruby-saml to the patched versions v1.17.
{
"severity": "CRITICAL",
"cwe_ids": [
"CWE-347"
],
"nvd_published_at": null,
"github_reviewed_at": "2024-09-11T21:08:26Z",
"github_reviewed": true
}