← Πίσω στην αναζήτηση CVE

CVE-2026-54605

OAuth

Περιγραφή

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer-s configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.

CVSS 7.2EPSS 0.132%Κίνδυνος 0.73
Προβολή πηγής
Δημοσίευση
2026-07-28 17:16:52
Επηρεαζόμενες εκδόσεις
>=0.5.5,<1.1.6
Τύπος
Βιβλιοθήκη
Τελευταία τροποποίηση
2026-07-28 18:17:22
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N