{"id":"GHSA-fgmx-8h93-26fh","summary":"omniauth-oauth2 Cross-Site Request Forgery vulnerability","details":"Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem prior to 1.1.1 for Ruby allows remote attackers to hijack the authentication of users for requests that modify session state.","aliases":["CVE-2012-6134"],"modified":"2024-12-05T05:39:59.934310Z","published":"2017-10-24T18:33:37Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:34:38Z","nvd_published_at":null,"cwe_ids":["CWE-352"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-6134"},{"type":"WEB","url":"https://github.com/Shopify/omniauth-shopify-oauth2/pull/1"},{"type":"WEB","url":"https://github.com/intridea/omniauth-oauth2/pull/25"},{"type":"PACKAGE","url":"https://github.com/Shopify/omniauth-shopify-oauth2"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-oauth2/CVE-2012-6134.yml"},{"type":"WEB","url":"https://web.archive.org/web/20170312020947/https://gist.github.com/homakov/3673012"},{"type":"WEB","url":"http://rubysec.github.io/advisories/CVE-2012-6134"},{"type":"WEB","url":"http://seclists.org/oss-sec/2013/q1/304"}],"affected":[{"package":{"name":"omniauth-oauth2","ecosystem":"RubyGems","purl":"pkg:gem/omniauth-oauth2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.1"}]}],"versions":["1.0.0","1.0.0.beta1","1.0.0.pr1","1.0.0.pr2","1.0.0.rc1","1.0.0.rc2","1.0.1","1.0.2","1.0.3","1.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-fgmx-8h93-26fh/GHSA-fgmx-8h93-26fh.json"}}],"schema_version":"1.9.0"}