PT-2014-2831 · Ruby · Omniauth-Facebook

Homakov

·

Published

2014-05-13

·

Updated

2017-10-24

·

CVE-2013-4562

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions omniauth-facebook gem versions 1.4.1 through 1.4.1
Description The issue allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter, due to improper storage of the session parameter.
Recommendations For omniauth-facebook gem version 1.4.1, update to version 1.5.0 or later to resolve the issue.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4562
GHSA-CF36-985G-V73C

Affected Products

Omniauth-Facebook