Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
by miya - Wednesday October 9, 2024 at 11:07 AM
#1
The flaw, tracked as CVE-2024-45409, arises from an issue in the OmniAuth-SAML and Ruby-SAML libraries, which GitLab uses to handle SAML-based authentication.

The vulnerability occurs when the SAML response sent by an identity provider (IdP) to GitLab contains a misconfiguration or is manipulated.

Specifically, the flaw involves insufficient validation of key elements in the SAML assertions, such as the extern_uid (external user ID), which is used to uniquely identify a user across different systems.

An attacker can craft a malicious SAML response that tricks GitLab into recognizing them as authenticated users, bypassing SAML authentication and gaining access to the GitLab instance.

The CVE-2024-45409 flaw impacts GitLab 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10, and all prior releases of those branches.

Hidden Content
You must register or login to view this content.

This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Suspected Scamming | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you feel this is incorrect.
Reply
#2
Thanks brother, I hope it would have a dork to find affected systems as well
Reply
#3
(10-09-2024, 11:16 AM)vjvjvjvj Wrote: Thanks brother, I hope it would have a dork to find affected systems as well

of course brother
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Suspected Scamming | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you feel this is incorrect.
Reply
#4
Pretty explained. Thanks!
Reply
#5
please let me see thanks
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you feel this is incorrect.
Reply
#6
Thanks brother, I hope it would have a dork to find affected systems as well
Reply
#7
tyyy i will try to use it...
Reply
#8
very usefull, i hope you have posted the poc
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you feel this is incorrect.
Reply
#9
Pretty explained. Thanks!
Reply
#10
Commenting to check out the vuln
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Exploit Hikvision Camera cctv A3g00n 160 4,528 2 hours ago
Last Post: 0Xnulled
  AMSI Bypass with Powershell W11 pompompurinn 43 7,913 Yesterday, 02:42 AM
Last Post: v3nuzc0d3r2325
  !Next.js Middleware Bypass (CVE-2025-29927) Rat1337 16 756 08-03-2025, 11:17 AM
Last Post: icebear223
  Exploit Safety-net PoC Inexorable_Baer 2 241 08-02-2025, 08:53 AM
Last Post: Inexorable_Baer
  Apache Superset Authentication Bypass metadata 0 103 08-02-2025, 12:50 AM
Last Post: metadata

Forum Jump:


 Users browsing this thread: