PT-2022-9003 · Omniauth+1 · Omniauth+1

Published

2022-08-18

·

Updated

2024-06-18

·

CVE-2020-36599

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OmniAuth versions prior to 1.9.2 OmniAuth versions prior to 2.0
Description The issue is related to the lib/omniauth/failure endpoint.rb file in OmniAuth, where the message key value is not properly escaped. This could potentially lead to security issues.
Recommendations For OmniAuth versions prior to 1.9.2, update to version 1.9.2 or later. For OmniAuth versions prior to 2.0, update to version 2.0 or later. As a temporary workaround, consider restricting access to the failure endpoint until a patch is available.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36599
GHSA-PM55-QFXR-H247

Affected Products

Debian
Omniauth