VDB
Sign up
HIGH7.5

GHSA-9pr6-grf4-x2fr

Omniauth allows POST parameters to be stored in session

Quick fix

GHSA-9pr6-grf4-x2fr — omniauth: upgrade to the fixed version with the command below.

bundle update omniauth

Details

In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/omniauth
Introduced in: 0Fixed in: 1.3.2
Fixbundle update omniauth

References