Bugzilla – Bug 1202556
VUL-0: CVE-2020-36599: rubygem-omniauth: lib/omniauth/failure_endpoint.rb in OmniAuth before 2.0 does not escape the message_key value
Last modified: 2022-08-19 08:15:04 UTC
CVE-2020-36599 lib/omniauth/failure_endpoint.rb in OmniAuth before 2.0 does not escape the message_key value. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-36599 http://www.cvedetails.com/cve/CVE-2020-36599/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36599 https://github.com/omniauth/omniauth/commit/43a396f181ef7d0ed2ec8291c939c95e3ed3ff00#diff-575abda9deb9b1a77bf534e898a923029b9a61e991d626db88dc6e8b34260aa2
Affected: - openSUSE:Backports:SLE-15-SP3/rubygem-omniauth 1.8.1 - openSUSE:Backports:SLE-15-SP4/rubygem-omniauth 1.8.1 - openSUSE:Factory/rubygem-omniauth 2.1.0