Releases70
Frequency2 months 2 weeks
Last Release
Downloads213M
A generalized Rack framework for multiple-provider authentication.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.