Skip to content

Pulling upstream master#1

Open
otb wants to merge 734 commits intoslides:masterfrom
SAML-Toolkits:master
Open

Pulling upstream master#1
otb wants to merge 734 commits intoslides:masterfrom
SAML-Toolkits:master

Conversation

@otb
Copy link

@otb otb commented Oct 6, 2016

No description provided.

johnnyshields and others added 30 commits January 19, 2025 18:04
…ion bypass via Signature Wrapping attack allowed due parser differential
Update ruby-saml version in README
Adapt tests and CI/CD improvements
Check message bytesize before Base64 validation
…w to force SP-Initiate flow and Prevent Reply Attacks
…Zlib::Inflate (#779)

Improve the inflate method. Prevent potential DoS vulnerability in Zlib::Inflate by limiting the maximum decompressed size. The data is now inflated in chunks.
CVE-2025-66567 and CVE-2025-66568 affects ruby-saml <= 1.12.4. Use ruby-saml 1.18.1 instead.
Updated vulnerability notice to reflect affected versions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.