Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Omniauth\-Facebook
(Madeofcode)Repositories | https://github.com/mkdynamic/omniauth-facebook |
#Vulnerabilities | 1 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2014-05-13 | CVE-2013-4562 | The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter. | Omniauth\-Facebook | N/A |