Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-11027

Опубликовано: 10 июн. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 10
CVSS3: 9.8

Описание

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

РелизСтатусПримечание
bionic

ignored

end of standard support, was deferred
devel

not-affected

2.9.2debian-1
esm-apps/bionic

deferred

2023/07/13
esm-apps/focal

not-affected

2.9.2debian-1
esm-apps/jammy

not-affected

2.9.2debian-1
esm-apps/noble

not-affected

2.9.2debian-1
esm-apps/xenial

deferred

2023/07/13
esm-infra-legacy/trusty

DNE

focal

not-affected

2.9.2debian-1
groovy

not-affected

2.9.2debian-1

Показывать по

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
больше 6 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

CVSS3: 9.8
nvd
больше 6 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

CVSS3: 9.8
debian
больше 6 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable ...

CVSS3: 9.8
github
больше 6 лет назад

ruby-openid SSRF via claimed_id request

10 Critical

CVSS2

9.8 Critical

CVSS3