Back to Database
Status published
Unknown
CVE-2015-20108
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows...
Vulnerability Description
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-20108
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/SAML-Toolkits/ruby-saml/pull/225
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/OSVDB-124991.yml
- https://github.com/SAML-Toolkits/ruby-saml/compare/v0.9.2...v1.0.0
- https://github.com/SAML-Toolkits/ruby-saml/commit/9853651b96b99653ea8627d757d46bfe62ab6448
- https://security.netapp.com/advisory/ntap-20230703-0003/
Affected Vendor
onelogin
View all reports →Affected Software
ruby-saml
Vulnerable Versions:
0
Timeline
Official Publish:
May 27th, 2023
Last Modified:
January 14th, 2025
Added to House:
July 19th, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.