Lucene search

K
ubuntucveUbuntu.comUB:CVE-2019-11027
HistoryJun 10, 2019 - 12:00 a.m.

CVE-2019-11027

2019-06-1000:00:00
ubuntu.com
ubuntu.com
8

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.005 Low

EPSS

Percentile

76.9%

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable
flaw. This library is used by Rails web applications to integrate with
OpenID Providers. Severity can range from medium to critical, depending on
how a web application developer chose to employ the ruby-openid library.
Developers who based their OpenID integration heavily on the “example app”
provided by the project are at highest risk.

Bugs

Notes

Author Note
emitorino The fix in https://github.com/openid/ruby-openid/pull/121 breaks login flows. For issue details please see https://github.com/openid/ruby-openid/issues/125 As of 2023/07/13 proposed fix has not been reviewed https://github.com/openid/ruby-openid/pull/128. Marking as deferred to see if it will eventually be fixed or not.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchruby-openid< anyUNKNOWN
ubuntu16.04noarchruby-openid< anyUNKNOWN

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.005 Low

EPSS

Percentile

76.9%