VYPR

RubyGems package

samlr

pkg:gem/samlr

Vulnerabilities (1)

  • CVE-2018-20857HigJul 26, 2019
    affected < 2.6.2fixed 2.6.2

    Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with [email protected] followed by <!---->. and then the attacker's domain name.