PT-2023-19865 · Rails+1 · Rails+1

Ankane

·

Publicado

2023-02-02

·

Atualizado

2025-03-26

·

CVE-2023-25015

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Clockwork Web versions prior to 0.1.2 Rails versions prior to 5.2
Description The issue allows Cross-Site Request Forgery (CSRF) attacks, which work by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, actions include enabling and disabling jobs.
Recommendations For Clockwork Web versions prior to 0.1.2, upgrade to version 0.1.2 or later. For Rails versions prior to 5.2, upgrade to version 5.2 or later.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-25015
GHSA-P4XX-W6FR-C4W9

Produtos afetados

Clockwork Web
Rails