VDB
Sign up
MEDIUM

GHSA-cf36-985g-v73c

omniauth-facebook Cross-Site Request Forgery vulnerability

Quick fix

GHSA-cf36-985g-v73c — omniauth-facebook: upgrade to the fixed version with the command below.

bundle update omniauth-facebook

Details

The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/omniauth-facebook
Introduced in: 1.4.1Fixed in: 1.5.0
Fixbundle update omniauth-facebook

References