cbcvebase.
CVE-2013-1812
published 2013-12-12

CVE-2013-1812: The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an…

PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.13%
79.9th percentile
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianruby-openid< ruby-openid 2.1.8debian-6 (bookworm)ruby-openid 2.1.8debian-6 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
janrainruby-openid<= 2.2.1
janrainruby-openid
janrainruby-openid>= 0 < 2.1.8debian-62.1.8debian-6
janrainruby-openid>= 0 < 2.1.8debian-62.1.8debian-6
janrainruby-openid>= 0 < 2.1.8debian-62.1.8debian-6
janrainruby-openid>= 0 < 2.1.8debian-62.1.8debian-6
janrainruby-openid>= 0 < 2.2.22.2.2

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_redhat5.8MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.