PT-2013-3403 · Ruby · Ruby-Openid

Ubercomp

·

Publicado

2013-12-12

·

Atualizado

2017-10-24

·

CVE-2013-1812

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ruby-openid versions prior to 2.2.2
Description The issue allows remote OpenID providers to cause a denial of service, specifically CPU consumption, through two methods: (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack. XEE attack refers to a type of attack that exploits the use of external entities in XML documents to cause a denial of service.
Recommendations For versions prior to 2.2.2, update to version 2.2.2 or later to resolve the issue. As a temporary workaround, consider restricting the size of XRDS documents and disabling XML Entity Expansion to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1812
GHSA-6C8P-QPHV-668V

Produtos afetados

Ruby-Openid