Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
by miyako - Wednesday October 9, 2024 at 11:07 AM
#11
very nicely done sir
Reply
#12
(Oct 09, 2024, 11:07 AM)miyako Wrote: The flaw, tracked as CVE-2024-45409, arises from an issue in the OmniAuth-SAML and Ruby-SAML libraries, which GitLab uses to handle SAML-based authentication.

The vulnerability occurs when the SAML response sent by an identity provider (IdP) to GitLab contains a misconfiguration or is manipulated.

Specifically, the flaw involves insufficient validation of key elements in the SAML assertions, such as the extern_uid (external user ID), which is used to uniquely identify a user across different systems.

An attacker can craft a malicious SAML response that tricks GitLab into recognizing them as authenticated users, bypassing SAML authentication and gaining access to the GitLab instance.

The CVE-2024-45409 flaw impacts GitLab 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10, and all prior releases of those branches.

I'll search dorks and it's done! thank you
Reply
#13
thank you. i hope it works fine
Reply
#14
gonna test my office gitlab
Reply
#15
thanks using this now ))
Reply
#16
Thanks for your contribution
Reply
#17
Pretty explained. Thanks!
Reply
#18
Thanks for the info and the explanation will help in future
Reply
#19
Thanks for sharing!
Reply
#20
of course brother



This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Attempted Scamming Thread-DATABASE-Database-Empik-com-Poland-11-825-92 | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  {SECRET} DATABASE OF EXPLOITS lulagain 436 26,564 2 hours ago
Last Post: nobcoderfck
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 108 13,727 2 hours ago
Last Post: nobcoderfck
  Ban Any Discord Exploit phineasfisherman 7 457 9 hours ago
Last Post: sniperx86
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 42 3,772 11 hours ago
Last Post: d39ug
  New Zer0 Day Wordpress A3g00n 81 3,399 Yesterday, 03:06 AM
Last Post: DirtyEra

Forum Jump:


 Users browsing this forum: 1 Guest(s)