CyberzSOC

Applicability
← Back to CVE-2024-45409

CVE-2024-45409

SAML-Toolkits

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

OSV.dev (incl. GHSA)
precedence 80 · revised 2026-09-11
12 affected 10 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2024-11-11
2 affected
CVE List v5 (ADP/Vulnrichment)
precedence 55 · revised 2024-11-11
3 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (27)

Product Status Versions Remediation Source
gitlab affected < 16.11.10 vendor fix → 16.11.10 osv BIT-gitlab-2024-45409
gitlab affected >= 17.0.0, < 17.0.8 vendor fix → 17.0.8 osv BIT-gitlab-2024-45409
gitlab affected >= 17.1.0, < 17.1.8 vendor fix → 17.1.8 osv BIT-gitlab-2024-45409
gitlab affected >= 17.2.0, < 17.2.7 vendor fix → 17.2.7 osv BIT-gitlab-2024-45409
gitlab affected >= 17.3.0, < 17.3.3 vendor fix → 17.3.3 osv BIT-gitlab-2024-45409
https://github.com/omniauth/omniauth-saml affected <= 7a7ad49ad425f7ec17d77078bf4bd2dd46e918c5 none available osv
https://github.com/omniauth/omniauth-saml affected >= ed52758c272f5afe81e3304d1f4e436e30021a2a, <= f2a7a8459a77f9901750d43460f33d5a095ac28a none available osv
https://github.com/omniauth/omniauth-saml affected < 1ec5392bc506fe43a02dbb66b68741051c5ffeae vendor fix → 1ec5392bc506fe43a02dbb66b68741051c5ffeae osv
https://github.com/omniauth/omniauth-saml affected >= 5da850c36bbf678674f9321032df428139d7e434, < 1bc447f297b769d1a9abeb619ce074bd9c410a72 vendor fix → 1bc447f297b769d1a9abeb619ce074bd9c410a72 osv
https://github.com/omniauth/omniauth-saml affected < 4865d030cae9705ee5cdb12415c654c634093ae7 vendor fix → 4865d030cae9705ee5cdb12415c654c634093ae7 osv
ruby-saml affected < 1.12.3 vendor fix → 1.12.3 osv GHSA-jw9c-mfg7-9rx2
ruby-saml affected >= 1.13.0, < 1.17.0 vendor fix → 1.17.0 osv GHSA-jw9c-mfg7-9rx2
gitlab fixed 16.11.10 vendor fix → 16.11.10 osv BIT-gitlab-2024-45409
gitlab fixed 17.0.8 vendor fix → 17.0.8 osv BIT-gitlab-2024-45409
gitlab fixed 17.1.8 vendor fix → 17.1.8 osv BIT-gitlab-2024-45409
gitlab fixed 17.2.7 vendor fix → 17.2.7 osv BIT-gitlab-2024-45409
gitlab fixed 17.3.3 vendor fix → 17.3.3 osv BIT-gitlab-2024-45409
https://github.com/omniauth/omniauth-saml fixed 1ec5392bc506fe43a02dbb66b68741051c5ffeae vendor fix → 1ec5392bc506fe43a02dbb66b68741051c5ffeae osv
https://github.com/omniauth/omniauth-saml fixed 1bc447f297b769d1a9abeb619ce074bd9c410a72 vendor fix → 1bc447f297b769d1a9abeb619ce074bd9c410a72 osv
https://github.com/omniauth/omniauth-saml fixed 4865d030cae9705ee5cdb12415c654c634093ae7 vendor fix → 4865d030cae9705ee5cdb12415c654c634093ae7 osv
ruby-saml fixed 1.12.3 vendor fix → 1.12.3 osv GHSA-jw9c-mfg7-9rx2
ruby-saml fixed 1.17.0 vendor fix → 1.17.0 osv GHSA-jw9c-mfg7-9rx2
SAML-Toolkits/ruby-saml SAML-Toolkits · ruby-saml affected < 1.12.3 none available cve_cna
SAML-Toolkits/ruby-saml SAML-Toolkits · ruby-saml affected >= 1.13.0, < 1.17.0 none available cve_cna
omniauth/omniauth-saml omniauth · omniauth-saml affected <= 2.1.0 none available cve_adp
onelogin/ruby-saml onelogin · ruby-saml affected < 1.12.3 none available cve_adp
onelogin/ruby-saml onelogin · ruby-saml affected >= 1.13.0, < 1.17.0 none available cve_adp

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.