CVE List

CVE-2019-11027

Severe 9.8

Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the "example app" provided by the project are at highest risk.

Published June 10, 2019.

Affected software

Get alerts for Openid Ruby-openid

Reference links