simi/omniauth-facebook

simi/omniauth-facebook

Releases24
Frequency5 months 1 week
Last Release
Stars1.27K
Facebook OAuth2 Strategy for OmniAuth

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.