The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.
References
Configurations
Information
Published : 2014-05-13 08:55
Updated : 2014-05-14 10:19
NVD link : CVE-2013-4562
Mitre link : CVE-2013-4562
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
madeofcode
- omniauth-facebook