MEDIUM
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack
Published Dec 12, 2013
4.3
MEDIUMCVSS 2.0
EPSS 2.13%
Description
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
Affected products
No data.
Configuration 1
OR
- 17
- 18
Configuration 2
OR
- ≤ 2.2.1
- 2.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120204.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120361.html vendor-advisoryx_refsource_FEDORA
- http://www.openwall.com/lists/oss-security/2013/03/03/8 mailing-listx_refsource_MLISTPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=918134 x_refsource_CONFIRM
- https://github.com/advisories/GHSA-6c8p-qphv-668v Advisory
- https://github.com/openid/ruby-openid/blob/master/CHANGELOG.md x_refsource_CONFIRM
- https://github.com/openid/ruby-openid/commit/a3693cef06049563f5b4e4824f4d3211288508ed x_refsource_CONFIRMExploitPatch
- https://github.com/openid/ruby-openid/pull/43 x_refsource_CONFIRM
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-openid/CVE-2013-1812.yml
- https://nvd.nist.gov/vuln/detail/CVE-2013-1812
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120204.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120361.html | vendor-advisoryx_refsource_FEDORA | |
| http://www.openwall.com/lists/oss-security/2013/03/03/8 | mailing-listx_refsource_MLISTPatch | |
| https://bugzilla.redhat.com/show_bug.cgi?id=918134 | x_refsource_CONFIRM | |
| https://github.com/advisories/GHSA-6c8p-qphv-668v | Advisory | |
| https://github.com/openid/ruby-openid/blob/master/CHANGELOG.md | x_refsource_CONFIRM | |
| https://github.com/openid/ruby-openid/commit/a3693cef06049563f5b4e4824f4d3211288508ed | x_refsource_CONFIRMExploitPatch | |
| https://github.com/openid/ruby-openid/pull/43 | x_refsource_CONFIRM | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-openid/CVE-2013-1812.yml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2013-1812 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 12, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-1812
CISA Vulnrichment
GHSA-6C8P-QPHV-668V Updated n/a