CyberzSOC

Publication detail
← Back to advisories & guidance

2025-011: Critical Vulnerabilities in Gitlab ↗ source

March 14, 2025 CERT-EU Advisory

Summary

It is recommended updating affected assets as soon as possible. The critical vulnerabilities CVE-2025-25291 and CVE-2025-25292 affect the ruby-saml library. If exploited, it could allow an attacker with access to a valid signed SAML document to impersonate another user within the same SAML IdP environment. This can result in unauthorised access to another user’s account. The vulnerability CVE-2025-27407 is a high-severity remote code execution issue in the Ruby graphql library.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-25291 9.3 Critical SAML-Toolkits ruby-saml ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-…
CVE-2025-25292 9.3 Critical SAML-Toolkits ruby-saml ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-…
CVE-2025-27407 9.1 Critical rmosolgo graphql-ruby graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.