Записи OpenID
7 опубликованных записей вендора openid.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 42,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-11027Эксплойта нет | Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw.openid · ruby-openid | Критическая9,8 | — | 3,0 % | 10 июн. 2019 г. |
30Наблюдать | CVE-2007-1652Эксплойта нет | OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, andopenid · openid | Высокая7,5 | — | 1,3 % | 23 мар. 2007 г. |
28Наблюдать | CVE-2007-5173Proof of concept | PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute openid · openid · CWE-94 | Средняя6,8 | — | 2,8 % | 3 окт. 2007 г. |
27Наблюдать | CVE-2007-1651Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enableopenid · openid | Средняя6,8 | — | 1,4 % | 23 мар. 2007 г. |
24Наблюдать | CVE-2008-3280Proof of concept | It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Randopenid · openid · CWE-338 | Средняя5,9 | — | 4,0 % | 21 мая 2021 г. |
24Наблюдать | CVE-2011-4314Эксплойта нет | message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Fopenid · openid4java · CWE-20 | Средняя5,8 | — | 3,1 % | 27 янв. 2012 г. |
24Наблюдать | CVE-2019-9837Эксплойта нет | Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redireopenid · openid connect · CWE-601 | Средняя6,1 | — | 1,3 % | 21 мар. 2019 г. |
- CVE-2019-1102740В плане
Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %openid · ruby-openid10 июн. 2019 г.
- CVE-2007-165230Наблюдать
OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openid · openid23 мар. 2007 г.
- CVE-2007-517328Наблюдать
PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute
СредняяCVSS 6,8Proof of conceptEPSS 3 %openid · openid3 окт. 2007 г.
- CVE-2007-165127Наблюдать
Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enable
СредняяCVSS 6,8Эксплойта нетEPSS 1 %openid · openid23 мар. 2007 г.
- CVE-2008-328024Наблюдать
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Rand
СредняяCVSS 5,9Proof of conceptEPSS 4 %openid · openid21 мая 2021 г.
- CVE-2011-431424Наблюдать
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay F
СредняяCVSS 5,8Эксплойта нетEPSS 3 %openid · openid4java27 янв. 2012 г.
- CVE-2019-983724Наблюдать
Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redire
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openid · openid connect21 мар. 2019 г.