Vulnerabilities |
5 via 5 paths |
|---|---|
Dependencies |
91 |
Source |
GitHub |
Find, fix and prevent vulnerabilities in your code.
high severity
- Module: bundler-audit
- Introduced through: bundler-audit@0.9.3
Detailed paths
-
Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb › bundler-audit@0.9.3
GPL-3.0 license
medium severity
- Vulnerable module: llhttp
- Introduced through: omniauth_openid_federation@2.0.0
Detailed paths
-
Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb › omniauth_openid_federation@2.0.0 › http@6.0.4 › llhttp@0.6.2
Overview
llhttp is a set of Ruby bindings for llhttp.
Affected versions of this package are vulnerable to HTTP Request Smuggling via llhttp. The parse ignores chunk extensions when parsing the body of chunked requests.
Remediation
There is no fixed version for llhttp.
References
medium severity
- Vulnerable module: llhttp
- Introduced through: omniauth_openid_federation@2.0.0
Detailed paths
-
Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb › omniauth_openid_federation@2.0.0 › http@6.0.4 › llhttp@0.6.2
Overview
llhttp is a set of Ruby bindings for llhttp.
Affected versions of this package are vulnerable to HTTP Request Smuggling via llhttp. The HTTP parser accepts requests with a space (SP) right after the header name before the colon.
Remediation
There is no fixed version for llhttp.
References
medium severity
- Vulnerable module: llhttp
- Introduced through: omniauth_openid_federation@2.0.0
Detailed paths
-
Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb › omniauth_openid_federation@2.0.0 › http@6.0.4 › llhttp@0.6.2
Overview
llhttp is a set of Ruby bindings for llhttp.
Affected versions of this package are vulnerable to HTTP Request Smuggling when the llhttp parser in the http module does not correctly parse and validate Transfer-Encoding headers.
Remediation
A fix was pushed into the master branch but not yet published.
References
medium severity
- Vulnerable module: llhttp
- Introduced through: omniauth_openid_federation@2.0.0
Detailed paths
-
Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb › omniauth_openid_federation@2.0.0 › http@6.0.4 › llhttp@0.6.2
Overview
llhttp is a set of Ruby bindings for llhttp.
Affected versions of this package are vulnerable to HTTP Request Smuggling. The llhttp parser in the http module does not correctly handle multi-line Transfer-Encoding headers.
Remediation
There is no fixed version for llhttp.
References
medium severity
- Vulnerable module: llhttp
- Introduced through: omniauth_openid_federation@2.0.0
Detailed paths
-
Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb › omniauth_openid_federation@2.0.0 › http@6.0.4 › llhttp@0.6.2
Overview
llhttp is a set of Ruby bindings for llhttp.
Affected versions of this package are vulnerable to HTTP Request Smuggling.
when the llhttp parser in the http module does not adequately delimit HTTP requests with CRLF sequences.
Remediation
There is no fixed version for llhttp.
References
medium severity
- Module: llhttp
- Introduced through: omniauth_openid_federation@2.0.0
Detailed paths
-
Introduced through: amkisko/omniauth_openid_federation.rb@amkisko/omniauth_openid_federation.rb › omniauth_openid_federation@2.0.0 › http@6.0.4 › llhttp@0.6.2
MPL-2.0 license