Back to Database
Status published
Medium
CVE-2013-4562
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store...
Vulnerability Description
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-4562
Credits & Attribution
No credits recorded in the NVD database.
References
- http://seclists.org/oss-sec/2013/q4/264
- http://www.osvdb.org/99693
- https://github.com/mkdynamic/omniauth-facebook/commit/ccfcc26fe7e34acbd75ad4a095fd01ce5ff48ee7
- https://groups.google.com/d/msg/ruby-security-ann/-tJHNlTiPh4/9SJxdEWLIawJ
- http://osvdb.org/ref/99/omniauth-facebook_gem.txt
- http://seclists.org/oss-sec/2013/q4/267
Affected Vendor
madeofcode
View all reports →Affected Software
omniauth-facebook
Vulnerable Versions:
1.4.1
Timeline
Official Publish:
May 13th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.