A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rails | Sep 28, 2020 | Jul 2, 2020 |
| Freebsd | — | Upgrade rubygem-activestorage52Upgrade rubygem-activesupport60Upgrade rubygem-activestorage60Upgrade rubygem-actionview60Upgrade rubygem-actionpack60Upgrade rubygem-actionview52Upgrade rubygem-activesupport52Upgrade rubygem-actionpack52 | May 20, 2020 | May 19, 2020 |
| Ruby_on_rails | — | Upgrade to the latest version of Ruby on Rails | Jul 13, 2020 | Jul 2, 2020 |
| Suse | — | Upgrade rmt-server-pubcloudUpgrade rmt-serverUpgrade ruby2.5-rubygem-actionpack-5_1Upgrade rmt-server-config | Nov 5, 2020 | May 18, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub