Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9pr6-grf4-x2fr

Опубликовано: 29 янв. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Omniauth allows POST parameters to be stored in session

In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.

Пакеты

Наименование

omniauth

rubygems
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

EPSS

Процентиль: 63%
0.00439
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.

CVSS3: 7.5
nvd
около 8 лет назад

In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.

CVSS3: 7.5
debian
около 8 лет назад

In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value ...

EPSS

Процентиль: 63%
0.00439
Низкий

7.5 High

CVSS3