Описание
PgHero gem allows CSRF
The PgHero gem through 2.6.0 for Ruby allows CSRF. PgHero normally uses the protect_from_forgery method from Rails to prevent CSRF. However, this defaults to :null_session, which has no effect on non-session based authentication methods. Thus the ruby gem is vulnerable with non-session based authentication methods like basic authentication.
Пакеты
Наименование
pghero
rubygems
Затронутые версииВерсия исправления
< 2.7.0
2.7.0