VDB
Sign up
MEDIUM

GHSA-6c8p-qphv-668v

Denial of service in ruby-openid

Quick fix

GHSA-6c8p-qphv-668v — ruby-openid: upgrade to the fixed version with the command below.

bundle update ruby-openid

Details

The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/ruby-openid
Introduced in: 0Fixed in: 2.2.2
Fixbundle update ruby-openid

References