Headline
GHSA-r364-2pj4-pf7f: ruby-saml vulnerable to XPath injection
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
ruby-saml vulnerable to XPath injection
Critical severity GitHub Reviewed Published May 27, 2023 to the GitHub Advisory Database • Updated Jun 6, 2023
Related news
CVE-2015-20108: Some features from the PR #197 (PR splitted) by pitbulk · Pull Request #225 · SAML-Toolkits/ruby-saml
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.