In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the environment of the callback phase.
| Software | From | Fixed in |
|---|---|---|
| omniauth / omniauth | - | 1.3.2 |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
omniauth
|
- | 1.3.2 |