PT-2023-10309 · Ruby · Ruby-Saml

Reedloden

·

Published

2023-05-27

·

Updated

2025-01-14

·

CVE-2015-20108

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ruby-saml gem versions prior to 1.0.0
Description The issue allows XPath injection and code execution in the ruby-saml gem because prepared statements are not used. This is related to the xml security.rb file.
Recommendations For versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the xml security.rb file until a patch is available.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2015-20108
GHSA-R364-2PJ4-PF7F

Affected Products

Ruby-Saml