{"id":"GHSA-6c8p-qphv-668v","summary":"Denial of service in ruby-openid","details":"The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.","aliases":["CVE-2013-1812"],"modified":"2024-12-05T05:43:55.233706Z","published":"2017-10-24T18:33:37Z","database_specific":{"github_reviewed_at":"2020-06-16T21:18:51Z","nvd_published_at":"2013-12-12T18:55:10Z","cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1812"},{"type":"WEB","url":"https://github.com/openid/ruby-openid/pull/43"},{"type":"WEB","url":"https://github.com/openid/ruby-openid/commit/a3693cef06049563f5b4e4824f4d3211288508ed"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=918134"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6c8p-qphv-668v"},{"type":"PACKAGE","url":"https://github.com/openid/ruby-openid"},{"type":"WEB","url":"https://github.com/openid/ruby-openid/blob/master/CHANGELOG.md"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-openid/CVE-2013-1812.yml"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120204.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120361.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/03/03/8"}],"affected":[{"package":{"name":"ruby-openid","ecosystem":"RubyGems","purl":"pkg:gem/ruby-openid"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.2"}]}],"versions":["1.0","1.0.1","1.0.2","1.1.1","1.1.2","1.1.3","1.1.4","2.0.1","2.0.2","2.0.3","2.0.4","2.1.2","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.2.0","2.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-6c8p-qphv-668v/GHSA-6c8p-qphv-668v.json"}}],"schema_version":"1.9.0"}