Collected research
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409)
SAML assertion integrity rests on the digest inside the signed SignedInfo block matching a recomputed digest of the assertion. This analysis of CVE-2024-45409 shows Ruby-SAML read that digest with an unanchored XPath expression, so a DigestValue smuggled into the samlp:Extensions element was compared instead of the signed one, allowing a tampered assertion whose signature still verifies and authentication as any user on GitLab and other affected service providers.
Record
- Researcher
- Harsh Jaiswal and Rahul Maini
- Published by
- ProjectDiscovery
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Harsh Jaiswal and Rahul Maini, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .