Boletines de Vulnerabilidades

DSA-4109 ruby-omniauth - security update

   
Software afectado Debian
 
Lalith Rallabhandi discovered that OmniAuth, a Ruby library forimplementing multi-provider authentication in web applications,mishandled and leaked sensitive information. An attacker with access tothe callback environment, such as in the case of a crafted webapplication, can request authentication services from this module andaccess to the CSRF token.

More info:

https://www.debian.org/security/2018/dsa-4109