OmniAuth是一套利用Rack中间件实现的认证系统。 OmniAuth 1.3.2之前的版本中的strategy.rb文件存在安全漏洞,该漏洞源于程序没有正确的保护authenticity_token值。攻击者可利用该漏洞获取令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-12378 | ClamAV AntiVirus software 安全漏洞 | |
| CVE-2017-1000404 | CloudBees Jenkins Delivery Pipeline Plugin 跨站脚本漏洞 | |
| CVE-2018-6323 | GNU Binutils Binary File Descriptor库数字错误漏洞 | |
| CVE-2018-5750 | Linux kernel 安全漏洞 | |
| CVE-2016-6217 | Sophos PureMessage for UNIX 跨站脚本漏洞 | |
| CVE-2017-12374 | ClamAV AntiVirus software 安全漏洞 | |
| CVE-2017-12375 | ClamAV AntiVirus software 缓冲区错误漏洞 | |
| CVE-2017-12376 | ClamAV AntiVirus software 缓冲区错误漏洞 | |
| CVE-2017-12377 | ClamAV AntiVirus software 缓冲区错误漏洞 | |
| CVE-2017-1000403 | Jenkins Speaks! Plugin 安全漏洞 | |
| CVE-2017-12379 | ClamAV AntiVirus software 缓冲区错误漏洞 | |
| CVE-2017-12380 | ClamAV AntiVirus software 安全漏洞 | |
| CVE-2017-14521 | WonderCMS 安全漏洞 | |
| CVE-2017-14522 | WonderCMS 跨站脚本漏洞 | |
| CVE-2017-14523 | WonderCMS 安全漏洞 | |
| CVE-2017-17976 | Perfex CRM 安全漏洞 | |
| CVE-2018-6015 | WordPress Email Subscribers & Newsletters插件安全漏洞 | |
| CVE-2017-1000395 | CloudBees Jenkins 安全漏洞 | |
| CVE-2017-1000387 | CloudBees Jenkins Build-Publisher 安全漏洞 | |
| CVE-2017-1000388 | CloudBees Jenkins Dependency Graph Viewer插件安全漏洞 |
Showing top 20 of 35 CVEs. View all on vendor page → →
No comments yet