HIGHRubyGems →
omniauth-apple allows attacker to fake their email address during authentication
omniauth-apple allows attacker to fake their email address during authentication
Affected packages
- omniauth-apple— before 1.0.1
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/nhosoya/omniauth-apple/security/advisories/GHSA-49r3-2549-3633
- https://nvd.nist.gov/vuln/detail/CVE-2020-26254
- https://github.com/nhosoya/omniauth-apple/commit/b37d5409213adae2ca06a67fec14c8d3d07d9016
- https://github.com/nhosoya/omniauth-apple
- https://github.com/nhosoya/omniauth-apple/blob/master/CHANGELOG.md#101---2020-12-03
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-apple/CVE-2020-26254.yml
Structured record: https://osv.dev/vulnerability/GHSA-49r3-2549-3633
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta