CRITICAL9.8
GHSA-r364-2pj4-pf7f
ruby-saml vulnerable to XPath injection
Quick fix
GHSA-r364-2pj4-pf7f — ruby-saml: upgrade to the fixed version with the command below.
bundle update ruby-samlDetails
`xml_security.rb` in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-20108[ADVISORY]
- https://github.com/SAML-Toolkits/ruby-saml/pull/225[WEB]
- https://github.com/SAML-Toolkits/ruby-saml/commit/9853651b96b99653ea8627d757d46bfe62ab6448[WEB]
- https://github.com/SAML-Toolkits/ruby-saml[PACKAGE]
- https://github.com/SAML-Toolkits/ruby-saml/compare/v0.9.2...v1.0.0[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/CVE-2015-20108.yml[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/OSVDB-124991.yml[WEB]
- https://security.netapp.com/advisory/ntap-20230703-0003[WEB]
- https://security.snyk.io/vuln/SNYK-RUBY-RUBYSAML-20217[WEB]