Answer in brief
CVE-2013-4593 records a High severity (CVSS 7.5) missing auth vulnerability in omniauth-facebook Improper Authentication vulnerability. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Answer in brief
CVE-2013-4593 records a High severity (CVSS 7.5) missing auth vulnerability in omniauth-facebook Improper Authentication vulnerability. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Update omniauth-facebook to 1.5.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMissing Auth describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2013-4593 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| omniauth-facebookrubygems | >=0 <1.5.1 | 1.5.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by OSV (osv).
CVE-2013-4593 records a High severity (CVSS 7.5) missing auth vulnerability in omniauth-facebook Improper Authentication vulnerability. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for omniauth-facebook.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate omniauth-facebook to 1.5.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMissing Auth describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2013-4593 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| omniauth-facebookrubygems | >=0 <1.5.1 | 1.5.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by OSV (osv).
CVE-2013-4593 records a High severity (CVSS 7.5) missing auth vulnerability in omniauth-facebook Improper Authentication vulnerability. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for omniauth-facebook.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardRubyGem omniauth-facebook has an access token security vulnerability.
RubyGem omniauth-facebook has an access token security vulnerability.