CVE-2020-36599

Publication date

2022-08-18 22:48:07

Family

mitre

State

PUBLISHED

Description

lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.