google_sign_in
RubyGems2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting google_sign_inpage 1 of 1
- CVE-2025-57821MEDIUMCVSS 4.2EG 4.2✓ Fixed in 1.3.02025-08-27
vulnerable: 0.1 ... 1.2.1 (13 versions)
Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.0, it is possible to craft a malformed URL that passes the "same origin" check, resulting in the user being redirected to another origin. Rails appli…
- CVE-2025-58067MEDIUMCVSS 4.2EG 4.2✓ Fixed in 1.3.12025-08-29
vulnerable: 0.1 ... 1.3.0 (14 versions)
Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect a user to another origin if the "proceed_to" value in the session store is set to a protocol-relative URL. Normally the…
Check whether google_sign_in is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for google_sign_in CVEs against the assets you own.
Start Free Scan →