omniauth/omniauth-oauth2

omniauth/omniauth-oauth2

Releases24
Frequency7 months 1 week
Last Release
Stars511
An abstract OAuth2 strategy for OmniAuth.

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem 1.1.1 and earlier for Ruby allows remote attackers to hijack the authentication of users for requests that modify session state.