Release | Version |
---|---|
buster | 1.8.1-1 |
bullseye | 1.9.1-1 |
bookworm | 2.1.1-1 |
sid | 2.1.1-1 |
Bug | buster | bullseye | bookworm | sid | Description |
---|---|---|---|---|---|
CVE-2020-36599 | vulnerable (no DSA) | vulnerable | fixed | fixed | lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before ... |
CVE-2015-9284 | vulnerable (no DSA, ignored) | vulnerable (no DSA, ignored) | fixed | fixed | The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vuln ... |
Bug | Description |
---|---|
CVE-2017-18076 | In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value ... |
DSA / DLA | Description |
---|---|
DSA-4109-1 | ruby-omniauth - security update |