{"id":"GHSA-cf36-985g-v73c","summary":"omniauth-facebook Cross-Site Request Forgery vulnerability","details":"The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.","aliases":["CVE-2013-4562"],"modified":"2024-11-30T05:38:59.133292Z","published":"2017-10-24T18:33:37Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:31:10Z","nvd_published_at":"2014-05-13T15:55:04Z","cwe_ids":["CWE-352"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4562"},{"type":"WEB","url":"https://github.com/mkdynamic/omniauth-facebook/commit/ccfcc26fe7e34acbd75ad4a095fd01ce5ff48ee7"},{"type":"PACKAGE","url":"https://github.com/mkdynamic/omniauth-faceboo"},{"type":"WEB","url":"https://groups.google.com/d/msg/ruby-security-ann/-tJHNlTiPh4/9SJxdEWLIawJ"},{"type":"WEB","url":"http://seclists.org/oss-sec/2013/q4/264"},{"type":"WEB","url":"http://seclists.org/oss-sec/2013/q4/267"}],"affected":[{"package":{"name":"omniauth-facebook","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-facebook"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.4.1"},{"fixed":"1.5.0"}]}],"versions":["1.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-cf36-985g-v73c/GHSA-cf36-985g-v73c.json"}}],"schema_version":"1.9.0"}