Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvqr-r76c-wm5f

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Devise Token Auth vulnerable to Cross-site Scripting

An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's browser. This affects the fallback_render method in the omniauth callbacks controller.

Пакеты

Наименование

devise_token_auth

rubygems
Затронутые версииВерсия исправления

>= 0.1.33, < 1.1.3

1.1.3

EPSS

Процентиль: 73%
0.00759
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's browser. This affects the fallback_render method in the omniauth callbacks controller.

EPSS

Процентиль: 73%
0.00759
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79