GHSA-mvqr-r76c-wm5f
Dashboard / Vulnerabilities / GHSA-mvqr-r76c-wm5f
Summary: Devise Token Auth vulnerable to Cross-site Scripting
Details: An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's browser. This affects the `fallback_render` method in the omniauth callbacks controller.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-16751, https://github.com/lynndylanhurley/devise_token_auth/issues/1332, https://github.com/lynndylanhurley/devise_token_auth, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/devise_token_auth/CVE-2019-16751.yml
Affected packages
Package
Name: devise_token_auth
Purl: pkg:gem/devise_token_auth
Affected ranges
Type: ECOSYSTEM
Events:
