CVE

CVE-2020-36599

CVE-2020-36599

lib/omniauth/failure_endpoint.rb in OmniAuth before 2.0 does not escape the message_key value.

Source: CVE-2020-36599

Exit mobile version