VDB
Sign up
CRITICAL9.8

GHSA-fqfj-cmh6-hj49

ruby-openid SSRF via claimed_id request

Quick fix

GHSA-fqfj-cmh6-hj49 — ruby-openid: upgrade to the fixed version with the command below.

bundle update ruby-openid

Details

Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/ruby-openid
Introduced in: 0Fixed in: 2.9.0
Fixbundle update ruby-openid

References