Sha256: b604078fd3e031f53dae73c4af213918d9d60300ad261e3d64cce8128a5c06bd
Contents?: true
Size: 675 Bytes
Versions: 1
Compression:
Stored size: 675 Bytes
Contents
--- gem: omniauth-facebook cve: 2013-4562 osvdb: 99693 url: https://nvd.nist.gov/vuln/detail/CVE-2013-4562 title: omniauth-facebook Gem for Ruby Unspecified CSRF date: 2013-11-12 description: | omniauth-facebook Gem for Ruby contains a flaw as HTTP requests do not require multiple steps, explicit confirmation, or a unique token when performing certain sensitive actions. By tricking a user into following a specially crafted link, a context-dependent attacker can perform a Cross-Site Request Forgery (CSRF / XSRF) attack causing the victim to perform an unspecified action. cvss_v2: 6.8 patched_versions: - ">= 1.5.0" unaffected_versions: - "<= 1.4.0"
Version data entries
1 entries across 1 versions & 1 rubygems
Version | Path |
---|---|
bundler-audit-0.7.0.1 | data/ruby-advisory-db/gems/omniauth-facebook/CVE-2013-4562.yml |