The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade google_sign_in
to version 1.3.1 or higher.
google_sign_in is a Sign in (or up) with Google for Rails applications
Affected versions of this package are vulnerable to Open Redirect via the proceed_to
value in the session store when it is set to a protocol-relative URL. An attacker can redirect users to an unintended origin by submitting a crafted form from a malicious site, potentially leading to unauthorized redirection if the session value can be manipulated through chained attacks that modify OAuth2 request parameters.