CVE-2020-36599
18.08.2022, 23:15
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.Enginsight
| Vendor | Product | Version |
|---|---|---|
| omniauth | omniauth | 𝑥 < 1.9.2 |
| omniauth | omniauth | 2.0.0:pre.rc1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References