USN-7409-1: RubySAML vulnerabilities
It was discovered that ruby-saml did not correctly handle XML parsing. An attacker could possibly use this issue to perform a signature wrapping attack and bypass authentication. (CVE-2025-25291 and CVE-2025-25292) It was discovered that ruby-saml did not correctly handle decompressing SAML responses. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-25293)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7409-1?
The severity of USN-7409-1 is significant, as it allows attackers to potentially bypass authentication through a signature wrapping attack.
How do I fix USN-7409-1?
To fix USN-7409-1, update the ruby-saml package to the latest patched version available for your Ubuntu release.
Which versions of ruby-saml are affected by USN-7409-1?
All versions of ruby-saml prior to the respective patched versions mentioned in USN-7409-1 for supported Ubuntu releases are affected.
What types of attacks are possible with the vulnerability in USN-7409-1?
The vulnerability in USN-7409-1 could lead to signature wrapping attacks, potentially allowing for unauthorized access.
Is my system at risk if I use ruby-saml in an outdated Ubuntu version related to USN-7409-1?
Yes, systems using outdated versions of ruby-saml in the specified Ubuntu releases are at risk of exploitation due to this vulnerability.