Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-11027

Опубликовано: 10 июн. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10
CVSS3: 9.8

Описание

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

РелизСтатусПримечание
bionic

ignored

end of standard support, was deferred
devel

not-affected

2.9.2debian-1
esm-apps-legacy/xenial

deferred

2023/07/13
esm-apps/bionic

deferred

2023/07/13
esm-apps/focal

not-affected

2.9.2debian-1
esm-apps/jammy

not-affected

2.9.2debian-1
esm-apps/noble

not-affected

2.9.2debian-1
esm-apps/resolute

not-affected

2.9.2debian-1
esm-apps/xenial

ignored

end of ESM support, was deferred [2023/07/13]
esm-infra-legacy/trusty

DNE

Показывать по

EPSS

Процентиль: 86%
0.02968
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
около 7 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

CVSS3: 9.8
nvd
около 7 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

CVSS3: 9.8
debian
около 7 лет назад

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable ...

CVSS3: 9.8
github
около 7 лет назад

ruby-openid SSRF via claimed_id request

EPSS

Процентиль: 86%
0.02968
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3