Vulnerabilities

5 via 5 paths

Dependencies

91

Source

GitHub

Find, fix and prevent vulnerabilities in your code.

Issue type
  • 5
  • 2
Severity
  • 1
  • 6
Status
  • 7
  • 0
  • 0

high severity

GPL-3.0 license

  • Module: bundler-audit
  • Introduced through: bundler-audit@0.9.3

Detailed paths

  • Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb bundler-audit@0.9.3

GPL-3.0 license

medium severity

HTTP Request Smuggling

  • Vulnerable module: llhttp
  • Introduced through: omniauth_openid_federation@2.0.0

Detailed paths

  • Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb omniauth_openid_federation@2.0.0 http@6.0.4 llhttp@0.6.2

Overview

llhttp is a set of Ruby bindings for llhttp.

Affected versions of this package are vulnerable to HTTP Request Smuggling via llhttp. The parse ignores chunk extensions when parsing the body of chunked requests.

Remediation

There is no fixed version for llhttp.

References

medium severity

HTTP Request Smuggling

  • Vulnerable module: llhttp
  • Introduced through: omniauth_openid_federation@2.0.0

Detailed paths

  • Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb omniauth_openid_federation@2.0.0 http@6.0.4 llhttp@0.6.2

Overview

llhttp is a set of Ruby bindings for llhttp.

Affected versions of this package are vulnerable to HTTP Request Smuggling via llhttp. The HTTP parser accepts requests with a space (SP) right after the header name before the colon.

Remediation

There is no fixed version for llhttp.

References

medium severity

HTTP Request Smuggling

  • Vulnerable module: llhttp
  • Introduced through: omniauth_openid_federation@2.0.0

Detailed paths

  • Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb omniauth_openid_federation@2.0.0 http@6.0.4 llhttp@0.6.2

Overview

llhttp is a set of Ruby bindings for llhttp.

Affected versions of this package are vulnerable to HTTP Request Smuggling when the llhttp parser in the http module does not correctly parse and validate Transfer-Encoding headers.

Remediation

A fix was pushed into the master branch but not yet published.

References

medium severity

HTTP Request Smuggling

  • Vulnerable module: llhttp
  • Introduced through: omniauth_openid_federation@2.0.0

Detailed paths

  • Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb omniauth_openid_federation@2.0.0 http@6.0.4 llhttp@0.6.2

Overview

llhttp is a set of Ruby bindings for llhttp.

Affected versions of this package are vulnerable to HTTP Request Smuggling. The llhttp parser in the http module does not correctly handle multi-line Transfer-Encoding headers.

Remediation

There is no fixed version for llhttp.

References

medium severity

HTTP Request Smuggling

  • Vulnerable module: llhttp
  • Introduced through: omniauth_openid_federation@2.0.0

Detailed paths

  • Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb omniauth_openid_federation@2.0.0 http@6.0.4 llhttp@0.6.2

Overview

llhttp is a set of Ruby bindings for llhttp.

Affected versions of this package are vulnerable to HTTP Request Smuggling. when the llhttp parser in the http module does not adequately delimit HTTP requests with CRLF sequences.

Remediation

There is no fixed version for llhttp.

References

medium severity

MPL-2.0 license

  • Module: llhttp
  • Introduced through: omniauth_openid_federation@2.0.0

Detailed paths

  • Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb omniauth_openid_federation@2.0.0 http@6.0.4 llhttp@0.6.2

MPL-2.0 license