The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ruby-openid(RubyGems) | 0 | 2.2.2 | N/A |
CVSS Metrics