UBUNTU-CVE-2019-11027
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-11027
Summary:
Details: Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.
References: https://ubuntu.com/security/CVE-2019-11027, https://github.com/openid/ruby-openid/issues/122, https://marc.info/?l=openid-security&m=155154717027534&w=2, https://www.cve.org/CVERecord?id=CVE-2019-11027
Affected packages
Package
Name: ruby-openid
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
