Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rails | Jul 30, 2024 | Dec 16, 2009 |
| Gentoo Linux | — | Upgrade dev-ruby/rails. | Oct 30, 2017 | Dec 15, 2009 |
| Ruby_on_rails | — | Upgrade to the latest version of Ruby on Rails | Jan 3, 2020 | Dec 16, 2009 |
| Suse | — | Upgrade rubygem-actionpack-2_0Upgrade rubygem-actionpack-2_3Upgrade rubygem-actionpack-2_1Upgrade rubygem-actionpack | Feb 17, 2015 | Dec 15, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub