The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.
Loading...
Loading...
The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.
May 13, 2014
May 6, 2026
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| omniauth-facebook | 1.4.1 | 1.5.0 | — |
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-4562
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.