Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

1 omniauth vulnerability found in Gemfile.lock #972

Closed
LinuxSysAdmin opened this issue Oct 1, 2019 · 4 comments
Closed

1 omniauth vulnerability found in Gemfile.lock #972

LinuxSysAdmin opened this issue Oct 1, 2019 · 4 comments

Comments

@LinuxSysAdmin
Copy link

Please complete all sections.

Configuration

  • Provider Gem: omniauth-*
  • Ruby Version: 5.2.3
  • Framework: Rails
  • Platform: Ubuntu 16.04

Expected Behavior

Tell us what should happen.

After i deploy my Rails code at GitHUb it shows 1 omniauth vulnerability found in Gemfile.lock
Remediation
No patched version is available.

Actual Behavior

https://github.com/FreelancerMasum/finaldev/network/alert/Gemfile.lock/omniauth/open
Tell us what happens instead.
Screenshot from 2019-10-01 13-08-29

Steps to Reproduce

Please list all steps to reproduce the issue.

@alexventuraio
Copy link

Any proposal to fix it up?

@rrjohnson85
Copy link

Isn't this covered in the Wiki, https://github.com/omniauth/omniauth/wiki/Resolving-CVE-2015-9284?

@alexventuraio
Copy link

@rrjohnson85 yeah I see that we need to use a new gem to fix that issue.
One more question, if I'm using omniauth-github is there a way I can fix the same issue but in that gem?
Since the GitHub strategy gem is using omniauth gem I think that's way I get the same vulnerability issue :( .

Thanks in advance!

@BobbyMcWho
Copy link
Member

Duplicate of #960

@BobbyMcWho BobbyMcWho marked this as a duplicate of #960 Feb 14, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants