CVE-2015-20108: Command Injection
xmlsecurity.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
Other sources
xmlsecurity.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-20108?
CVE-2015-20108 has a high severity due to its potential for XPath injection and code execution.
How do I fix CVE-2015-20108?
To fix CVE-2015-20108, upgrade the ruby-saml gem to version 1.0.0 or later.
What is the impact of CVE-2015-20108?
The impact of CVE-2015-20108 includes the possibility of unauthorized code execution through XPath injection.
Which versions of the ruby-saml gem are affected by CVE-2015-20108?
Versions of the ruby-saml gem prior to 1.0.0 are affected by CVE-2015-20108.
Is CVE-2015-20108 specific to certain platforms?
CVE-2015-20108 affects the ruby-saml gem regardless of the platform, as long as the vulnerable versions are used.