omniauth-facebook
Facebook OAuth2 Strategy for OmniAuth
Activity
- Latest release
- 1mo ago
- Total releases
- 25
- Cadence
- ~3 months
- Last 12 months
- 1
Reach
- Stars
- 1.3k
Details
- License
- MIT
- First release
- Oct 29, 2011
| Version | Released | |
|---|---|---|
11.0.0
major
| ||
10.0.0
major
| ||
9.0.0
major
| ||
8.0.0
major
| ||
7.0.0
major
| ||
6.0.0
major
| ||
5.0.0
major
| ||
4.0.0
major
| ||
4.0.0.rc1
pre
| ||
3.0.0
major
| ||
2.0.1
patch
| ||
2.0.0
major
| ||
2.0.0.pre1
pre
| ||
1.6.0
minor
| ||
1.6.0.rc1
pre
| ||
1.5.1
patch
| ||
1.5.0
minor
1 CVE
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.4.1
patch
2 CVEs
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2013-4562
GHSA-cf36-985g-v73c
Oct 24, 2017
omniauth-facebook Cross-Site Request Forgery vulnerability
Medium
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter. Affected versions
1.4.1
Fixed in
1.5.0
References
Updated Nov 30, 2024 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.0.0
initial
1 CVE
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.0.0.rc2
pre
1 CVE
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
1.0.0.rc1
pre
1 CVE
CVE-2013-4593
GHSA-33vg-hpx5-pfxg
May 05, 2022
omniauth-facebook Improper Authentication vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
RubyGem omniauth-facebook has an access token security vulnerability. Affected versions
1.0.0
1.0.0.rc1
1.0.0.rc2
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
Fixed in
1.5.1
References
Updated Nov 08, 2023 · Source: OSV.dev |