Vulnerabilities > Onelogin > Ruby Saml > 1.1.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-04-17 | CVE-2017-11428 | Improper Authentication vulnerability in Onelogin Ruby-Saml OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. | 7.5 |
2017-01-23 | CVE-2016-5697 | XML Injection (aka Blind XPath Injection) vulnerability in Onelogin Ruby-Saml Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. | 5.0 |