漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OAuth: Cross-origin token-request redirects can expose signed request metadata
Vulnerability Description
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Ruby OAuth OAuth 信息泄露漏洞
Vulnerability Description
Ruby OAuth OAuth是Ruby OAuth组织开源的一款授权认证协议组件。 Ruby OAuth OAuth 0.5.5版本至1.1.6之前版本存在安全漏洞,该漏洞源于解析Location header时跟随重定向,可能改变消费者配置并暴露签名OAuth请求元数据(包括Authorization header)给跨域主机。
CVSS Information
N/A
Vulnerability Type
N/A