CRITICAL9.8
GHSA-fqfj-cmh6-hj49
ruby-openid SSRF via claimed_id request
Quick fix
GHSA-fqfj-cmh6-hj49 — ruby-openid: upgrade to the fixed version with the command below.
bundle update ruby-openidDetails
Ruby OpenID (aka ruby-openid) through 2.8.0 is vulnerable to SSRF. Ruby-openid performs discovery first, and then verification. This allows an attacker to change the URL used for discovery and trick the server into connecting to the URL, which might be a private server not publicly accessible. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-11027[ADVISORY]
- https://github.com/openid/ruby-openid/issues/122[WEB]
- https://github.com/openid/ruby-openid/commit/d181a8a2099c64365a1d24b29f6b6b646673a131[WEB]
- https://github.com/openid/ruby-openid[PACKAGE]
- https://github.com/openid/ruby-openid/releases/tag/v2.9.0[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-openid/CVE-2019-11027.yml[WEB]
- https://lists.debian.org/debian-lts-announce/2019/10/msg00014.html[WEB]
- https://marc.info/?l=openid-security&m=155154717027534&w=2[WEB]
- https://security.gentoo.org/glsa/202003-09[WEB]