Boletines de Vulnerabilidades |
DSA-4109 ruby-omniauth - security update |
|
| Software afectado | Debian |
|
Lalith Rallabhandi discovered that OmniAuth, a Ruby library forimplementing multi-provider authentication in web applications,mishandled and leaked sensitive information. An attacker with access tothe callback environment, such as in the case of a crafted webapplication, can request authentication services from this module andaccess to the CSRF token. More info: https://www.debian.org/security/2018/dsa-4109 |
|














