Debian Package Tracker
Register | Log in
Subscribe

ruby-omniauth

flexible authentication system utilizing Rack middleware

Choose email to subscribe with

general
  • source: ruby-omniauth (main)
  • version: 2.1.1-1
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Pirate Praveen [DMD] – Utkarsh Gupta [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.8.1-1
  • o-o-bpo: 1.9.1-1~bpo10+1
  • oldstable: 1.9.1-1
  • stable: 2.1.1-1
  • testing: 2.1.1-1
  • unstable: 2.1.1-1
versioned links
  • 1.8.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.1-1~bpo10+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-omniauth (1 bugs: 0, 1, 0, 0)
action needed
2 low-priority security issues in bullseye low

There are 2 open security issues in bullseye.

1 issue left for the package maintainer to handle:
  • CVE-2020-36599: (needs triaging) lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.

You can find information about how to handle this issue in the security team's documentation.

1 ignored issue:
  • CVE-2015-9284: The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account.
Created: 2022-07-04 Last update: 2023-06-29 15:18
news
[rss feed]
  • [2023-01-24] ruby-omniauth 2.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-22] Accepted ruby-omniauth 2.1.1-1 (source) into unstable (Nilesh Patra)
  • [2022-10-28] ruby-omniauth 2.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-10-24] Accepted ruby-omniauth 2.1.0-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-09-10] ruby-omniauth 2.0.4-2 MIGRATED to testing (Debian testing watch)
  • [2022-09-08] Accepted ruby-omniauth 2.0.4-2 (source) into unstable (Antonio Terceiro)
  • [2022-09-07] Accepted ruby-omniauth 2.0.4-1 (source) into experimental (Antonio Terceiro)
  • [2021-06-10] Accepted ruby-omniauth 2.0.4-1~exp1 (source) into experimental (Antonio Terceiro)
  • [2020-09-15] Accepted ruby-omniauth 1.9.1-1~bpo10+1 (source all) into buster-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-04-02] ruby-omniauth 1.9.1-1 MIGRATED to testing (Debian testing watch)
  • [2020-03-29] Accepted ruby-omniauth 1.9.1-1 (source) into unstable (Utkarsh Gupta)
  • [2019-12-31] Accepted ruby-omniauth 1.9.0-1~bpo10+1 (source all) into buster-backports, buster-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2019-12-27] ruby-omniauth 1.9.0-1 MIGRATED to testing (Debian testing watch)
  • [2019-12-24] Accepted ruby-omniauth 1.9.0-1 (source) into unstable (Samyak Jain) (signed by: Praveen Arimbrathodiyil)
  • [2018-05-22] Accepted ruby-omniauth 1.8.1-1~bpo9+1 (source all) into stretch-backports, stretch-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-04-30] ruby-omniauth 1.8.1-1 MIGRATED to testing (Debian testing watch)
  • [2018-04-25] Accepted ruby-omniauth 1.8.1-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-02-27] ruby-omniauth 1.6.1-2 MIGRATED to testing (Debian testing watch)
  • [2018-02-22] Accepted ruby-omniauth 1.6.1-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-02-10] Accepted ruby-omniauth 1.2.1-1+deb8u1 (source all) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Pirate Praveen) (signed by: Luciano Bello)
  • [2018-02-10] Accepted ruby-omniauth 1.3.1-1+deb9u1 (source all) into proposed-updates->stable-new, proposed-updates (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-02-02] ruby-omniauth 1.3.1-2 MIGRATED to testing (Debian testing watch)
  • [2018-01-31] Accepted ruby-omniauth 1.3.1-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2017-07-24] Accepted ruby-omniauth 1.6.1-1 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2016-03-18] ruby-omniauth 1.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2016-03-12] Accepted ruby-omniauth 1.3.1-1 (source) into unstable (Rahulkrishnan R A) (signed by: Praveen Arimbrathodiyil)
  • [2015-07-21] ruby-omniauth 1.2.2-3 MIGRATED to testing (Britney)
  • [2015-07-15] Accepted ruby-omniauth 1.2.2-3 (source all) into unstable (Antonio Terceiro)
  • [2015-05-03] ruby-omniauth 1.2.2-2 MIGRATED to testing (Britney)
  • [2015-04-27] Accepted ruby-omniauth 1.2.2-2 (source all) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.1.1-1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing