PT-2023-19865 · Rails+1 · Rails+1
Ankane
·
Publicado
2023-02-02
·
Atualizado
2025-03-26
·
CVE-2023-25015
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Clockwork Web versions prior to 0.1.2
Rails versions prior to 5.2
Description
The issue allows Cross-Site Request Forgery (CSRF) attacks, which work by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, actions include enabling and disabling jobs.
Recommendations
For Clockwork Web versions prior to 0.1.2, upgrade to version 0.1.2 or later.
For Rails versions prior to 5.2, upgrade to version 5.2 or later.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Clockwork Web
Rails