CVE-2015-20108
27.05.2023, 19:15
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
| Vendor | Product | Version |
|---|---|---|
| onelogin | ruby-saml | 𝑥 < 1.0.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References