CVE-2019-16751
24.09.2019, 18:15
An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's browser. This affects the fallback_render method in the omniauth callbacks controller.
Vendor | Product | Version |
---|---|---|
devise_token_auth_project | devise_token_auth | 0.1.33 ≤ 𝑥 ≤ 1.1.2 |
𝑥
= Vulnerable software versions