Known Vulnerabilities for products from Omniauth
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Omniauth".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44707 json | Not Provided | 2026-05-26 | 2026-05-26 | |
| CVE-2020-36599 json | lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value. | 9.8 - CRITICAL | 2022-08-18 | 2022-08-19 |
| CVE-2017-18076 json | In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GE... | 7.5 - HIGH | 2018-01-26 | 2019-10-03 |
| CVE-2015-9284 json | The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part ... | 8.8 - HIGH | 2019-04-26 | 2020-11-13 |
Known software with vulnerabilities from Omniauth
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Omniauth | Omniauth | - |