logo

Active Exploitation Of SAML Vulnerability CVE-2024-45409

ID: 777c127f-f10f-5caf-9d74-2296327276b2

STIX ID: report--777c127f-f10f-5caf-9d74-2296327276b2

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-12-16

Date Updated: 2026-07-16

...
...

This report details CVE-2024-45409, a critical (CVSS 9.8) authentication-bypass flaw in Ruby-SAML allowing forged SAML Responses to authenticate as arbitrary users; GitLab issued patches for affected releases and Cyble observed active scanning/exploitation attempts, with recommended mitigations including updating Ruby-SAML/GitLab, enabling MFA, and disabling SAML two-factor bypass.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.