Debian Security Advisory 4109-1

Discussion in 'News Aggregator' started by Packet Storm, 13 Feb 2018.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 4109-1 - Lalith Rallabhandi discovered that OmniAuth, a Ruby library for implementing multi-provider authentication in web applications, mishandled and leaked sensitive information. An attacker with access to the callback environment, such as in the case of a crafted web application, can request authentication services from this module and access to the CSRF token.

    Continue reading...
     

Share This Page

Loading...