lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
| Software | From | Fixed in |
|---|---|---|
omniauth
|
- | 1.9.2 |
omniauth
|
2.0.0.pre.rc1 | 2.0.0.pre.rc1.x |
omniauth
|
2.0.0.pre.rc1 | 2.0.0 |
| omniauth / omniauth | 2.0.0-pre.rc1 | 2.0.0-pre.rc1.x |
| omniauth / omniauth | - | 1.9.2 |