{"id":"UBUNTU-CVE-2019-11027","details":"Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applications to integrate with OpenID Providers. Severity can range from medium to critical, depending on how a web application developer chose to employ the ruby-openid library. Developers who based their OpenID integration heavily on the \"example app\" provided by the project are at highest risk.","modified":"2025-10-24T04:47:36Z","published":"2019-06-10T19:29:00Z","upstream":["CVE-2019-11027"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-11027"},{"type":"REPORT","url":"https://github.com/openid/ruby-openid/issues/122"},{"type":"REPORT","url":"https://marc.info/?l=openid-security&m=155154717027534&w=2"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2019-11027"}],"affected":[{"package":{"name":"ruby-openid","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ruby-openid@2.7.0debian-1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7.0debian-1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.7.0debian-1","binary_name":"ruby-openid"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11027.json"}},{"package":{"name":"ruby-openid","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ruby-openid@2.7.0debian-1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7.0debian-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-openid","binary_version":"2.7.0debian-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-11027.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}