Back

HIGH

rubygem-omniauth: request phase of the OmniAuth Ruby gem is vulnerable to Cross-Site Request Forgery leading to connection without user intent

Published Apr 26, 2019

Description

The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account.

Affected products

Remediation

Red Hat statement

Red Hat CloudForms 4.5 is on maintenance support phase, thus only critical issues will be fixed.

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Apr 26, 2019
Updated Aug 6, 2024
Reserved Apr 9, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 27, 2015
GHSA-WW4X-RWQ6-QPGF