CVE-2015-20108
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
27/05/2023
Last modified:
14/01/2025
Description
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:onelogin:ruby-saml:*:*:*:*:*:*:*:* | 1.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/SAML-Toolkits/ruby-saml/commit/9853651b96b99653ea8627d757d46bfe62ab6448
- https://github.com/SAML-Toolkits/ruby-saml/compare/v0.9.2...v1.0.0
- https://github.com/SAML-Toolkits/ruby-saml/pull/225
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/OSVDB-124991.yml
- https://security.netapp.com/advisory/ntap-20230703-0003/
- https://github.com/SAML-Toolkits/ruby-saml/commit/9853651b96b99653ea8627d757d46bfe62ab6448
- https://github.com/SAML-Toolkits/ruby-saml/compare/v0.9.2...v1.0.0
- https://github.com/SAML-Toolkits/ruby-saml/pull/225
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/OSVDB-124991.yml
- https://security.netapp.com/advisory/ntap-20230703-0003/



