Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8166

Опубликовано: 02 июл. 2020
Источник: debian
EPSS Низкий

Описание

A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:5.2.4.3+dfsg-1package
railsnot-affectedstretchpackage
railsnot-affectedjessiepackage

Примечания

  • https://weblog.rubyonrails.org/2020/5/18/Rails-5-2-4-3-and-6-0-3-1-have-been-released

  • https://github.com/rails/rails/commit/d124f19287f4892c72ca54da728a781591c6fca1 (5.2)

  • per-form CSRF token introduced in 5.x: https://github.com/rails/rails/commit/3e98819e20bc113343d4d4c0df614865ad5a9d3a

EPSS

Процентиль: 62%
0.00443
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 5 лет назад

A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.

CVSS3: 3.7
redhat
около 5 лет назад

A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.

CVSS3: 4.3
nvd
около 5 лет назад

A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.

suse-cvrf
больше 1 года назад

Security update for rubygem-actionpack-5_1

CVSS3: 4.3
github
около 5 лет назад

Ability to forge per-form CSRF tokens in Rails

EPSS

Процентиль: 62%
0.00443
Низкий