CVE-2017-11428: Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
Last updated 20 January 2025
Other sources
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11428?
CVE-2017-11428 has been classified as a medium severity vulnerability.
How do I fix CVE-2017-11428?
To mitigate CVE-2017-11428, upgrade to a version of OneLogin Ruby-SAML that is later than 1.6.0.
What systems are affected by CVE-2017-11428?
CVE-2017-11428 affects OneLogin Ruby-SAML versions 1.6.0 and earlier.
What type of vulnerability is CVE-2017-11428?
CVE-2017-11428 is a SAML signature bypass vulnerability resulting from improper XML handling.
Can CVE-2017-11428 allow data manipulation without detection?
Yes, CVE-2017-11428 allows an attacker to manipulate SAML data without invalidating cryptographic signatures.