RubySec

Providing security resources for the Ruby community

GHSA-vp9c-fpxx-744v (personnummer): Validation bypass vulnerability

ADVISORIES

GEM

personnummer

PATCHED VERSIONS

  • >= 1.3.1

DESCRIPTION

Impact

This vulnerability impacts users who rely on the last four digits of personnummer to be a real personnummer.

Workaround

The issue arises from the regular expression allowing the first three digits in the last four digits of the personnummer to be 000, which is invalid. To mitigate this without upgrading, a check on the last four digits can be made to make sure it’s not 000x.