The omniauth-facebook gem 1.4.1 prior to 1.5.0 does not properly store the session parameter, which allows remote malicious users to conduct cross-site request forgery (CSRF) attacks via the state parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
madeofcode omniauth-facebook 1.4.1 |