Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem 1.1.1 and earlier for Ruby allows remote attackers to hijack the authentication of users for requests that modify session state.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RubyGems omniauth-oauth2 跨站请求伪造漏洞
Vulnerability Description
RubyGems是RubyGems组织的一款Ruby程序包管理器,它主要用于发布和管理Ruby程序包。 RubyGems omniauth-oauth2 gem 1.1.1和早期版本中存在跨站请求伪造漏洞。远程攻击者利用该漏洞在授权用户的会话上下文中执行某些操作,进而获得未授权访问到受影响应用程序的权限,也可能存在其他攻击。
CVSS Information
N/A
Vulnerability Type
N/A