xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
| Software | From | Fixed in |
|---|---|---|
| onelogin / ruby-saml | - | 1.0.0 |
ruby-saml
|
- | 1.0.0 |