Логотип exploitDog
bind:CVE-2021-29435
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-29435

Количество 2

Количество 2

nvd логотип

CVE-2021-29435

почти 5 лет назад

trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker to create a form that will bypass Rails' built-in CSRF protection when submitted by a victim with a trestle-auth admin session. This potentially allows an attacker to alter protected data, including admin account credentials. The vulnerability has been fixed in trestle-auth 0.4.2 released to RubyGems.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-h8hx-2c5r-32cf

почти 5 лет назад

Cross-Site Request Forgery (CSRF) in trestle-auth

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-29435

trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker to create a form that will bypass Rails' built-in CSRF protection when submitted by a victim with a trestle-auth admin session. This potentially allows an attacker to alter protected data, including admin account credentials. The vulnerability has been fixed in trestle-auth 0.4.2 released to RubyGems.

CVSS3: 8.1
0%
Низкий
почти 5 лет назад
github логотип
GHSA-h8hx-2c5r-32cf

Cross-Site Request Forgery (CSRF) in trestle-auth

CVSS3: 8.1
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу