Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11027

Опубликовано: 10 июн. 2019
Источник: debian

Описание

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-openidfixed2.9.2debian-1package
ruby-openidno-dsabusterpackage
ruby-openidno-dsastretchpackage

Примечания

  • https://github.com/openid/ruby-openid/issues/122

  • https://github.com/openid/ruby-openid/issues/122#issuecomment-520304211

  • https://github.com/openid/ruby-openid/commit/8a4c31a6740a949cdc29d956c276ba3c4021dfa8

  • https://github.com/openid/ruby-openid/commit/f526132c6cb5d9195351c16ed36dced4ca3db496

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

CVSS3: 5.9
redhat
больше 6 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

CVSS3: 9.8
nvd
больше 6 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

CVSS3: 9.8
github
больше 6 лет назад

ruby-openid SSRF via claimed_id request