CVE-2020-36599

CRITICAL

OmniAuth <1.9.2, <2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.

Scores

CVSS v3 9.8
EPSS 0.0062
EPSS Percentile 70.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-116
Status published
Products (3)
omniauth/omniauth 2.0.0 pre.rc1
omniauth/omniauth < 1.9.2
rubygems/omniauth 0 - 1.9.2RubyGems
Published Aug 18, 2022
Tracked Since Feb 18, 2026