Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
by miyako - Wednesday October 9, 2024 at 11:07 AM
#11
very nicely done sir
Reply
#12
(10-09-2024, 11:07 AM)miyako Wrote: The flaw, tracked as CVE-2024-45409, arises from an issue in the OmniAuth-SAML and Ruby-SAML libraries, which GitLab uses to handle SAML-based authentication.

The vulnerability occurs when the SAML response sent by an identity provider (IdP) to GitLab contains a misconfiguration or is manipulated.

Specifically, the flaw involves insufficient validation of key elements in the SAML assertions, such as the extern_uid (external user ID), which is used to uniquely identify a user across different systems.

An attacker can craft a malicious SAML response that tricks GitLab into recognizing them as authenticated users, bypassing SAML authentication and gaining access to the GitLab instance.

The CVE-2024-45409 flaw impacts GitLab 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10, and all prior releases of those branches.

I'll search dorks and it's done! thank you
Reply
#13
thank you. i hope it works fine
Reply
#14
gonna test my office gitlab
Reply
#15
thanks using this now ))
Reply
#16
Thanks for your contribution
Reply
#17
Pretty explained. Thanks!
Reply
#18
Thanks for the info and the explanation will help in future
Reply
#19
Thanks for sharing!
Reply
#20
of course brother

This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Attempted Scamming Thread-DATABASE-Database-Empik-com-Poland-11-825-92 | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Help Microsoft Teams Gif Exploit guniess0x 0 3 1 hour ago
Last Post: guniess0x
  Ban Any Discord Exploit PhineasFisher 6 295 02-08-2026, 11:49 PM
Last Post: skype
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 73 02-07-2026, 03:32 PM
Last Post: cysc
  POC CVE-2025-24071 caca28sapo1 15 805 02-07-2026, 08:53 AM
Last Post: hacker0123
  HPE OneView RCE Exploit [CVE-2025-37164] Hawx01 8 261 02-06-2026, 07:08 PM
Last Post: hacker0123



 Users browsing this thread: