{"id":"GHSA-pm55-qfxr-h247","summary":"OmniAuth's `lib/omniauth/failure_endpoint.rb` does not escape `message_key` value","details":"lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.","aliases":["CVE-2020-36599"],"modified":"2023-11-08T04:03:48.034548Z","published":"2022-08-19T00:00:16Z","database_specific":{"nvd_published_at":"2022-08-18T23:15:00Z","cwe_ids":["CWE-116"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-08-31T18:47:40Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-36599"},{"type":"WEB","url":"https://github.com/omniauth/omniauth/commit/43a396f181ef7d0ed2ec8291c939c95e3ed3ff00#diff-575abda9deb9b1a77bf534e898a923029b9a61e991d626db88dc6e8b34260aa2"},{"type":"PACKAGE","url":"https://github.com/omniauth/omniauth"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth/CVE-2020-36599.yml"},{"type":"WEB","url":"https://rubygems.org/gems/omniauth/versions/1.9.2"}],"affected":[{"package":{"name":"omniauth","ecosystem":"RubyGems","purl":"pkg:gem/omniauth"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.2"}]}],"versions":["0.0.1","0.0.3","0.0.4","0.0.5","0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.2.0","0.2.0.beta1","0.2.0.beta2","0.2.0.beta3","0.2.0.beta4","0.2.0.beta5","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.3.0","0.3.0.rc3","0.3.2","1.0.0","1.0.0.beta1","1.0.0.pr1","1.0.0.pr2","1.0.0.rc1","1.0.0.rc2","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.2.1","1.2.2","1.3.0","1.3.1","1.3.2","1.4.0","1.4.1","1.4.2","1.4.3","1.5.0","1.6.0","1.6.1","1.7.0","1.7.1","1.8.0","1.8.1","1.9.0","1.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-pm55-qfxr-h247/GHSA-pm55-qfxr-h247.json"}},{"package":{"name":"omniauth","ecosystem":"RubyGems","purl":"pkg:gem/omniauth"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0.pre.rc1"},{"fixed":"2.0.0"}]}],"versions":["2.0.0.pre.rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-pm55-qfxr-h247/GHSA-pm55-qfxr-h247.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}