## https://sploitus.com/exploit?id=47E14B22-1DD1-5BEB-8127-3235F7EAE5BF
# Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
This script exploits the [CVE-2024-45409](https://nvd.nist.gov/vuln/detail/CVE-2024-45409) that allows an unauthenticated attacker with access to any signed SAML document issued by the IDP to forge a SAML Response/Assertion and gain access as any user on GitLab.
All the following GitLab (CE/EE) versions are vulnerable:
* You are being redirected.
```
## References
* https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/
* https://github.com/advisories/GHSA-jw9c-mfg7-9rx2
* https://blog.projectdiscovery.io/ruby-saml-gitlab-auth-bypass/
* https://nvd.nist.gov/vuln/detail/CVE-2024-45409
* https://www.cvedetails.com/cve/CVE-2024-45409/