SCA: security update for omniauth-apple (GHSA-49r3-2549-3633)

high Tenable Cloud Security Plugin ID 410080

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- omniauth-apple is the OmniAuth strategy for "Sign In with Apple" (RubyGem omniauth-apple). In omniauth-
apple before version 1.0.1 attackers can fake their email address during authentication. This
vulnerability impacts applications using the omniauth-apple strategy of OmniAuth and using the info.email
field of OmniAuth's Auth Hash Schema for any kind of identification. The value of this field may be set to
any value of the attacker's choice including email addresses of other users. Applications not using
info.email for identification but are instead using the uid field are not impacted in the same manner.
Note, these applications may still be negatively affected if the value of info.email is being used for
other purposes. Applications using affected versions of omniauth-apple are advised to upgrade to omniauth-
apple version 1.0.1 or later. (CVE-2020-26254)

See Also

https://github.com/advisories/GHSA-49r3-2549-3633

Plugin Details

Severity: High

ID: 410080

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 50.87

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2020-26254

CVSS v3

Risk Factor: High

Base Score: 7.7

Temporal Score: 6.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/8/2020

Vulnerability Publication Date: 12/8/2020

Reference Information

CVE: CVE-2020-26254

cwe: CWE-290