Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-10522

Опубликовано: 05 июл. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rails_admin_project:rails_admin:*:*:*:*:*:ruby:*:*
Версия до 1.1.1 (исключая)

EPSS

Процентиль: 36%
0.00154
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.

CVSS3: 8.8
debian
больше 7 лет назад

rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forge ...

CVSS3: 8.8
github
больше 7 лет назад

Cross-site request forgery in rails_admin

EPSS

Процентиль: 36%
0.00154
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352