HIGH7.5
GHSA-9pr6-grf4-x2fr
Omniauth allows POST parameters to be stored in session
Quick fix
GHSA-9pr6-grf4-x2fr — omniauth: upgrade to the fixed version with the command below.
bundle update omniauthDetails
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-18076[ADVISORY]
- https://github.com/omniauth/omniauth/pull/867[WEB]
- https://github.com/omniauth/omniauth/pull/867/commits/71866c5264122e196847a3980c43051446a03e9b[WEB]
- https://bugs.debian.org/888523[WEB]
- https://github.com/omniauth/omniauth[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth/CVE-2017-18076.yml[WEB]
- https://www.debian.org/security/2018/dsa-4109[WEB]