VDB
Sign up
CRITICAL9.8

GHSA-r364-2pj4-pf7f

ruby-saml vulnerable to XPath injection

Quick fix

GHSA-r364-2pj4-pf7f — ruby-saml: upgrade to the fixed version with the command below.

bundle update ruby-saml

Details

`xml_security.rb` in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/ruby-saml
Introduced in: 0Fixed in: 1.0.0
Fixbundle update ruby-saml

References