ZeroHour

CVE-2017-18076

CVSS 3.1
7.5 high
EPSS
2%p81
Published
()
Modified
Description

In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.

Vendors
omniauthdebian
Products
omniauth, debian linux
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.