An authentication bypass vulnerability was found in ruby-saml due to a parser differential. ReXML and Nokogiri parse XML differently, the parsers can generate entirely different document structures from the same XML input. That allows an attacker to be able to execute a Signature Wrapping attack.
This issue may lead to authentication bypass.
{ "nvd_published_at": "2025-03-12T21:15:42Z", "cwe_ids": [ "CWE-347", "CWE-436" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2025-03-12T20:54:42Z" }