Descrição
OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer-s configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.
CVSS 7.2EPSS 0.132%Risco 0.73
Ver fonte- Publicação
- 2026-07-28 17:16:52
- Versões afetadas
- >=0.5.5,<1.1.6
- Tipo
- Biblioteca
- Última alteração
- 2026-07-28 18:17:22
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N