Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-4562
HistoryMay 13, 2014 - 3:55 p.m.

Cross site request forgery (csrf)

2014-05-1315:55:00
PRIOn knowledge base
www.prio-n.com

7.3 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.6%

The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.

CPENameOperatorVersion
omniauth-facebookeq1.4.1

7.3 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.6%

Related for PRION:CVE-2013-4562