CVE-2024-45409: GitLab

Critical severity, CVSS 9.8. EPSS: 10.7% chance of exploitation in the next 30 days.

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

Affected products

  • GitLab GitLab: before 16.11.10 (fixed in 16.11.10); from 17.0.0, before 17.0.8 (fixed in 17.0.8); from 17.1.0, before 17.1.8 (fixed in 17.1.8); from 17.2.0, before 17.2.7 (fixed in 17.2.7); from 17.3.0, before 17.3.3 (fixed in 17.3.3)
  • Omniauth Omniauth SAML: up to and including 1.10.3; version 2.0.0 only; version 2.1.0 only
  • Onelogin Ruby-SAML: before 1.12.3 (fixed in 1.12.3); from 1.13.0, before 1.17.0 (fixed in 1.17.0)

Published 2024-09-10. Last modified 2026-06-17.