Описание
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
rails | fixed | 2:5.2.4.3+dfsg-1 | package | |
rails | not-affected | stretch | package | |
rails | not-affected | jessie | package |
Примечания
https://weblog.rubyonrails.org/2020/5/18/Rails-5-2-4-3-and-6-0-3-1-have-been-released
https://github.com/rails/rails/commit/fbc7bec074b5ef9ae22f79ca5d9bafec7b276dd3 (5.2)
EPSS
Процентиль: 68%
0.00592
Низкий
Связанные уязвимости
CVSS3: 6.5
ubuntu
около 5 лет назад
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
CVSS3: 7.5
redhat
около 5 лет назад
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
CVSS3: 6.5
nvd
около 5 лет назад
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
EPSS
Процентиль: 68%
0.00592
Низкий