Server side template injection In ruby-saml
Description
ruby-saml vulnerable to XPath injection
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.