CVE
- Id
- 64509
- CVE No.
- CVE-2013-4562
- Status
- Candidate
- Description
- The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.
- Phase
- Assigned (20130612)
- Votes
- None (candidate not yet proposed)
- Comments