← Zurück zur CVE-Suche

CVE-2026-54605

OAuth

Beschreibung

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer-s configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.

CVSS 7.2EPSS 0.132%Risiko 0.73
Quelle öffnen
Veröffentlicht
2026-07-28 17:16:52
Betroffene Versionen
>=0.5.5,<1.1.6
Typ
Bibliothek
Zuletzt geändert
2026-07-28 18:17:22
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N