| Release | Version |
|---|---|
| bullseye | 1.9.1-1 |
| bookworm | 2.1.1-1 |
| trixie | 2.1.1-4 |
| forky | 2.1.4-1 |
| sid | 2.1.4-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2020-36599 | vulnerable (no DSA) | fixed | fixed | fixed | fixed | lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before ... |
| CVE-2015-9284 | vulnerable (no DSA, ignored) | fixed | fixed | fixed | fixed | The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vuln ... |
| Bug | Description |
|---|---|
| CVE-2017-18076 | In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value ... |
| DSA / DLA | Description |
|---|---|
| DSA-4109-1 | ruby-omniauth - security update |