Known Vulnerabilities for products from Onelogin
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Onelogin".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2017-11428 json | OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in su... | 9.8 - CRITICAL | 2019-04-17 | 2019-10-09 |
| CVE-2017-11427 json | OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in s... | 9.8 - CRITICAL | 2019-04-17 | 2019-10-09 |
| CVE-2016-10928 json | The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned us... | 7.5 - HIGH | 2019-08-22 | 2019-08-29 |
| CVE-2016-5697 json | Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. | Not Provided | 2017-01-23 | 2025-04-20 |
| CVE-2015-20108 json | xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared stateme... | 9.8 - CRITICAL | 2023-05-27 | 2023-07-03 |
Known software with vulnerabilities from Onelogin
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Onelogin | Onelogin Saml Sso | 1.0.0 |
| Application | Onelogin | Pythonsaml | 1.0.0 |
| Application | Onelogin | Ruby-saml | 0.2.0 |