Advisories for Gem/Better_errors package

2021

Cross-Site Request Forgery (CSRF)

better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It is also usable outside of Rails in any Rack app as Rack middleware. better_errors did not implement CSRF protection for its internal requests.