CVE-2013-1812

EUVD-2017-0174
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
janrainruby-openid
𝑥
≤ 2.2.1
janrainruby-openid
2.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ruby-openid
bookworm
2.9.2debian-2
fixed
bullseye
2.9.2debian-1
fixed
sid
2.9.2debian-3
fixed
trixie
2.9.2debian-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libopenid-ruby
hardy
dne
lucid
Fixed 2.1.7debian-1ubuntu0.1
released
oneiric
ignored
precise
Fixed 2.1.8debian-1ubuntu0.1
released
quantal
dne
raring
dne
ruby-openid
hardy
dne
lucid
dne
oneiric
dne
precise
dne
quantal
Fixed 2.1.8debian-5ubuntu0.1
released
raring
not-affected
Common Weakness Enumeration