Madeofcode maintains authentication integration libraries, specifically OAuth-related modules such as OmniAuth-Facebook that facilitate third-party login flows in web applications. The durable signal centers on cross-site request forgery vulnerabilities in these authentication integration points, reflecting the session and token-handling complexity inherent to federated identity protocols. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Madeofcode over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4562MEDIUM The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via t | May 13, 2014 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Madeofcode.
Media articles that mention a CVE ID that affects a product developed by Madeofcode — matched by CVE ID, not by vendor name.