CVE-2020-26254
Last modified
CVE-2020-26254 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during authentication. EPSS estimates a 1.32% chance of exploitation in the next 30 days.
Description
omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-apple before version 1.0.1 attackers can fake their email address during authentication. This vulnerability impacts applications using the omniauth-apple strategy of OmniAuth and using the info.email field of OmniAuth's Auth Hash Schema for any kind of identification. The value of this field may be set to any value of the attacker's choice including email addresses of other users. Applications not using info.email for identification but are instead using the uid field are not impacted in the same manner. Note, these applications may still be negatively affected if the value of info.email is being used for other purposes. Applications using affected versions of omniauth-apple are advised to upgrade to omniauth-apple version 1.0.1 or later.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Omniauth-Apple Project | Omniauth-Apple | < 1.0.1 |
References
- https://github.com/nhosoya/omniauth-apple/blob/master/CHANGELOG.md#101---2020-12-03Release Notes, Third Party Advisory
- https://github.com/nhosoya/omniauth-apple/commit/b37d5409213adae2ca06a67fec14c8d3d07d9016Patch, Third Party Advisory
- https://github.com/nhosoya/omniauth-apple/security/advisories/GHSA-49r3-2549-3633Exploit, Mitigation, Third Party Advisory
- https://github.com/nhosoya/omniauth-apple/blob/master/CHANGELOG.md#101---2020-12-03Release Notes, Third Party Advisory
- https://github.com/nhosoya/omniauth-apple/commit/b37d5409213adae2ca06a67fec14c8d3d07d9016Patch, Third Party Advisory
- https://github.com/nhosoya/omniauth-apple/security/advisories/GHSA-49r3-2549-3633Exploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-26254?
How severe is CVE-2020-26254?
How do I fix CVE-2020-26254?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-26249Red Discord Bot Dashboard is an easy-to-use interactive web …8.7
- CVE-2020-2625Vulnerability in the Enterprise Manager Base Platform produc…6
- CVE-2020-26250OAuthenticator is an OAuth login mechanism for JupyterHub. I…6.3
- CVE-2020-26251Open Zaak is a modern, open-source data- and services-layer …4.7
- CVE-2020-26252OpenMage is a community-driven alternative to Magento CE. In…7.2
- CVE-2020-26253Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3…5.9
- CVE-2020-26255Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3…9.1
- CVE-2020-26256Fast-csv is an npm package for parsing and formatting CSVs o…6.5
- CVE-2020-26257Matrix is an ecosystem for open federated Instant Messaging …6.5
- CVE-2020-26258XStream is a Java library to serialize objects to XML and ba…7.7
- CVE-2020-26259XStream is a Java library to serialize objects to XML and ba…6.8
- CVE-2020-2626Vulnerability in the Enterprise Manager Base Platform produc…6
Are you affected by CVE-2020-26254?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
