CVE-2017-18076

In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:omniauth:omniauth:*:*:*:*:*:ruby:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Information

Published : 2018-01-26 11:29

Updated : 2019-10-02 17:03


NVD link : CVE-2017-18076

Mitre link : CVE-2017-18076


JSON object : View

Advertisement

dedicated server usa

Products Affected

debian

  • debian_linux

omniauth

  • omniauth