Shopify/omniauth-shopify-oauth2

Shopify/omniauth-shopify-oauth2

Releases31
Frequency4 months 2 weeks
Last Release
Stars92
Shopify OAuth2 Strategy for OmniAuth 1.0

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem 1.1.1 and earlier for Ruby allows remote attackers to hijack the authentication of users for requests that modify session state.