CVE-2015-20108

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
2
PROJECTS

Description

xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.

A database of vulnerable Ruby Gems
GitHubGitHub
1.06K
SAML SSO for Ruby
GitHubGitHub
980