omniauth
A generalized Rack framework for multiple-provider authentication.
Activity
- Latest release
- 11mo ago
- Total releases
- 70
- Cadence
- ~23 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Apr 29, 2010
| Version | Released | |
|---|---|---|
2.1.4
patch
| ||
2.1.3
patch
| ||
2.1.2
patch
| ||
2.1.1
patch
| ||
1.9.2
patch
1 CVE
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.1.0
minor
| ||
2.0.4
patch
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
2.0.0
major
| ||
2.0.0.pre.rc1
pre
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.9.1
patch
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.9.0
minor
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.8.1
patch
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.8.0
minor
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.3
patch
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.7.1
patch
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.7.0
minor
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.6.1
patch
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.6.0
minor
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.5.0
minor
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.2
patch
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.1
patch
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.4.0
minor
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.2
patch
2 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.3.0
minor
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.3.1
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.2.2
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.2.1
minor
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.1.4
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.1.3
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.1.2
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.1.1
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.1.0
minor
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.3
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.2
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.1
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.0
major
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.0.rc2
pre
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.0.rc1
pre
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.3.2
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.0.beta1
pre
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.0.pr1
pre
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
1.0.0.pr2
pre
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.3.0
minor
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.3.0.rc3
pre
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.6
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.5
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev | ||
0.2.4
patch
3 CVEs
CVE-2020-36599
GHSA-pm55-qfxr-h247
Aug 19, 2022
OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 47 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0.pre.rc1
Fixed in
1.9.2
2.0.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2015-9284
GHSA-ww4x-rwq6-qpgf
May 29, 2019
OmniAuth Ruby gem Cross-site Request Forgery in request phase
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The request phase of the OmniAuth Ruby gem (1.9.2 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account. As of v2 OmniAuth no longer has the vulnerable configuration by default, but it is still possible to configure OmniAuth in such a way that the web application becomes vulnerable to Cross-Site Request Forgery. There is a recommended remediation described here. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 48 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.1
1.9.0
1.9.1
1.9.2
2.0.0.pre.rc1
Fixed in
2.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-18076
GHSA-9pr6-grf4-x2fr
Jan 29, 2018
Omniauth allows POST parameters to be stored in session
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase. Affected versions
0.0.1
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
+ 32 more Show less
0.2.0.beta1
0.2.0.beta2
0.2.0.beta3
0.2.0.beta4
0.2.0.beta5
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.0.rc3
0.3.2
1.0.0
1.0.0.beta1
1.0.0.pr1
1.0.0.pr2
1.0.0.rc1
1.0.0.rc2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1
1.2.2
1.3.0
1.3.1
Fixed in
1.3.2
References
Updated Dec 03, 2024 · Source: OSV.dev |