SB2019042605 - Cross-site request forgery in OmniAuth



SB2019042605 - Cross-site request forgery in OmniAuth

Published: April 26, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019042605
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cross-site request forgery (CVE-ID: CVE-2015-9284)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account.


Remediation

Install update from vendor's website.