HIGH7.5
GHSA-33vg-hpx5-pfxg
omniauth-facebook Improper Authentication vulnerability
Quick fix
GHSA-33vg-hpx5-pfxg — omniauth-facebook: upgrade to the fixed version with the command below.
bundle update omniauth-facebookDetails
RubyGem omniauth-facebook has an access token security vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-4593[ADVISORY]
- https://github.com/simi/omniauth-facebook/commit/115c0a768cd6f4b9bfae8900f8e3fc4fbeec3ad8[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89040[WEB]
- https://github.com/simi/omniauth-facebook[PACKAGE]
- https://security-tracker.debian.org/tracker/CVE-2013-4593[WEB]
- http://www.openwall.com/lists/oss-security/2013/11/18/6[WEB]