xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
References
Configurations
History
No history.
Information
Published : 2023-05-27 19:15
Updated : 2023-07-03 16:15
NVD link : CVE-2015-20108
Mitre link : CVE-2015-20108
CVE.ORG link : CVE-2015-20108
JSON object : View
Products Affected
onelogin
- ruby-saml
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')