← Back

Omniauth Facebook

omniauth-facebook

Vendor: Madeofcode • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Madeofcode
1Omniauth Facebook
May 6, 2026
May 13, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.