Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-r364-2pj4-pf7f: ruby-saml vulnerable to XPath injection

xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.

ghsa
#git#xpath#ruby

ruby-saml vulnerable to XPath injection

Critical severity GitHub Reviewed Published May 27, 2023 to the GitHub Advisory Database • Updated Jun 6, 2023

Related news

CVE-2015-20108: Some features from the PR #197 (PR splitted) by pitbulk · Pull Request #225 · SAML-Toolkits/ruby-saml

xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.