
Shopify/omniauth-shopify-oauth2
Releases31
Frequency4 months 2 weeks
Last Release
Stars92
Shopify OAuth2 Strategy for OmniAuth 1.0
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| — | 6.8 MEDIUM | ||
Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem 1.1.1 and earlier for Ruby allows remote attackers to hijack the authentication of users for requests that modify session state. | |||