RubySec

Providing security resources for the Ruby community

OSVDB-124383 (ruby-saml): Ruby-Saml Gem is vulnerable to entity expansion attacks

Ruby-Saml Gem is vulnerable to entity expansion attacks

Published: June 30, 2015

SECURITY IDENTIFIERS

GEM

ruby-saml

SEVERITY

CVSS v2.0: 3.9 (Low)

PATCHED VERSIONS

>= 1.0.0

DESCRIPTION

ruby-saml before 1.0.0 is vulnerable to entity expansion attacks.

RELATED