Web Hack List

Collected research

Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409)

SAML assertion integrity rests on the digest inside the signed SignedInfo block matching a recomputed digest of the assertion. This analysis of CVE-2024-45409 shows Ruby-SAML read that digest with an unanchored XPath expression, so a DigestValue smuggled into the samlp:Extensions element was compared instead of the signed one, allowing a tampered assertion whose signature still verifies and authentication as any user on GitLab and other affected service providers.

Record

Researcher
Harsh Jaiswal and Rahul Maini
Published by
ProjectDiscovery
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Harsh Jaiswal and Rahul Maini, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .