{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-16T20:18:15.549","vulnerabilities":[{"cve":{"id":"CVE-2019-16751","sourceIdentifier":"cve@mitre.org","published":"2019-09-24T18:15:11.030","lastModified":"2024-11-21T04:31:06.937","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's browser. This affects the fallback_render method in the omniauth callbacks controller."},{"lang":"es","value":"Se detectó un problema en Devise Token Auth versiones hasta 1.1.2. El end point de fallo omniauth es vulnerable a Cross Site Scripting (XSS) Reflejado por medio del parámetro message. Los atacantes no autenticados pueden diseñar una URL que ejecute una carga útil de JavaScript maliciosa en el navegador de la víctima. Esto afecta el método fallback_render en el controlador de devoluciones de llamada omniauth."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:devise_token_auth_project:devise_token_auth:*:*:*:*:*:*:*:*","versionStartIncluding":"0.1.33","versionEndIncluding":"1.1.2","matchCriteriaId":"DF5B1266-DAFD-4CA4-9818-93623F6A042A"}]}]}],"references":[{"url":"https://github.com/lynndylanhurley/devise_token_auth/issues/1332","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/lynndylanhurley/devise_token_auth/issues/1332","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}