Descripción
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer-s configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.
CVSS 7.2EPSS 0.132%Riesgo 0.73
Ver fuente- Publicación
- 2026-07-28 17:16:52
- Versiones afectadas
- >=0.5.5,<1.1.6
- Tipo
- Librería
- Última modificación
- 2026-07-28 18:17:22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N