CRITICAL
rubygem-ruby-openid: Unknown remotely exploitable flaw
Published Jun 10, 2019
9.8
CRITICALCVSS 3.0
EPSS 2.97%
Description
Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.
Affected products
No data.
- ≤ 2.8.0
No data.
Red Hat 3scale API Management Platform 2
ruby-openid
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat 3scale API Management Platform 2 | ruby-openid | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- https://access.redhat.com/security/cve/CVE-2019-11027 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1719494 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0532 Advisory
- https://github.com/advisories/GHSA-fqfj-cmh6-hj49 Advisory
- https://github.com/openid/ruby-openid/commit/d181a8a2099c64365a1d24b29f6b6b646673a131
- https://github.com/openid/ruby-openid/issues/122 x_refsource_MISC
- https://github.com/openid/ruby-openid/releases/tag/v2.9.0
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-openid/CVE-2019-11027.yml
- https://lists.debian.org/debian-lts-announce/2019/10/msg00014.html mailing-listx_refsource_MLIST
- https://marc.info/?l=openid-security&m=155154717027534&w=2 x_refsource_MISCMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11027
- https://security.gentoo.org/glsa/202003-09 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2019-11027
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-11027 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1719494 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0532 | Advisory | |
| https://github.com/advisories/GHSA-fqfj-cmh6-hj49 | Advisory | |
| https://github.com/openid/ruby-openid/commit/d181a8a2099c64365a1d24b29f6b6b646673a131 | ||
| https://github.com/openid/ruby-openid/issues/122 | x_refsource_MISC | |
| https://github.com/openid/ruby-openid/releases/tag/v2.9.0 | ||
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-openid/CVE-2019-11027.yml | ||
| https://lists.debian.org/debian-lts-announce/2019/10/msg00014.html | mailing-listx_refsource_MLIST | |
| https://marc.info/?l=openid-security&m=155154717027534&w=2 | x_refsource_MISCMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11027 | ||
| https://security.gentoo.org/glsa/202003-09 | vendor-advisoryx_refsource_GENTOO | |
| https://www.cve.org/CVERecord?id=CVE-2019-11027 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 10, 2019
Updated Aug 4, 2024
Reserved Apr 9, 2019
Link CVE-2019-11027
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-0532 GHSA-FQFJ-CMH6-HJ49 Assigner mitre
Published Jun 10, 2019
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2019-0532