10
CVSSv2

CVE-2019-11027

Published: 10/06/2019 Updated: 14/06/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Ruby OpenID (aka ruby-openid) up to and including 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openid ruby-openid

Vendor Advisories

Debian Bug report logs - #930388 ruby-openid: CVE-2019-11027 Package: src:ruby-openid; Maintainer for src:ruby-openid is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 11 Jun 2019 19:45:02 UTC Severity: grave Tags: ...