Onelogin OneLogin ruby-saml是美国Onelogin公司的一款基于Ruby的、用于单点登录(SSO)服务的SAML(安全断言标记语言)库。 OneLogin ruby-saml 1.0.0 之前版本存在安全漏洞,该漏洞源于不使用预设的语句,导致gem 中的 xml_security.rb 允许 XPath 注入和代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-26128 | 8.4 HIGH | keep-module-latest 命令注入漏洞 |
| CVE-2023-26129 | 8.4 HIGH | bwm-ng 命令注入漏洞 |
| CVE-2023-26127 | 7.8 HIGH | n158 命令注入漏洞 |
| CVE-2023-2928 | 6.3 MEDIUM | DedeCMS article_allowurl_edit.php code injection |
| CVE-2023-2927 | 6.3 MEDIUM | JIZHICMS TemplateController.php index server-side request forgery |
| CVE-2023-2926 | 5.4 MEDIUM | SeaCMS Picture Upload member.php denial of service |
No comments yet