CVE-2020-8167

Cross-Site Request Forgery (CSRF) in gem/rails

Identifiers

CVE-2020-8167

Package Slug

gem/rails

Vulnerability

Cross-Site Request Forgery (CSRF)

Description

A CSRF vulnerability exists in Rails' rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

Affected Versions

All versions before 5.2.4.3, all versions starting from 6.0.0 before 6.0.3.1

Solution

Upgrade to versions 5.2.4.3, 6.0.3.1 or above.

Last Modified

2020-06-25

source