Описание
omniauth-facebook Cross-Site Request Forgery vulnerability
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.
Пакеты
Наименование
omniauth-facebook
rubygems
Затронутые версииВерсия исправления
>= 1.4.1, < 1.5.0
1.5.0
Связанные уязвимости
nvd
больше 11 лет назад
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.
debian
больше 11 лет назад
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store t ...