We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 6a7c040 commit fa78136Copy full SHA for fa78136
1 file changed
CHANGELOG.md
@@ -46,6 +46,9 @@
46
* Add warning about the use of IdpMetadataParser class and SSRF
47
* CI: Migrate from Travis to Github Actions
48
49
+### 1.12.4 (Mar 12, 2025)
50
+* [#750](https://github.com/SAML-Toolkits/ruby-saml/pull/750) Fix vulnerabilities: CVE-2025-25291, CVE-2025-25292: SAML authentication bypass via Signature Wrapping attack allowed due parser differential. Fix vulnerability: CVE-2025-25293: Potential DOS abusing of compressed messages.
51
+
52
### 1.12.3 (Sep 10, 2024)
53
* Fix for critical vulnerability CVE-2024-45409: SAML authentication bypass via Incorrect XPath selector
54
0 commit comments