VDB

CVE-2015-20108

CVE-2015-20108 REJECTED

xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.

EPSS 0.40% · 61.1th percentile

Risk Scores

EPSS Score
0.40%
61.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSruby-saml1.4.1-1, 0

Timeline

  • May 28, 2023 EPSS Score
  • Jul 3, 2023 EPSS Score
  • Aug 8, 2023 EPSS Score
  • Sep 14, 2023 EPSS Score
  • Oct 20, 2023 EPSS Score
  • Nov 25, 2023 EPSS Score
  • Dec 31, 2023 EPSS Score
  • Feb 5, 2024 EPSS Score
  • Apr 18, 2024 EPSS Score
  • May 24, 2024 EPSS Score
  • Jun 29, 2024 EPSS Score
  • Aug 4, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›