Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tomekr

#31519of 53,624
8.1Total CVSS
Vulnerabilities · 1
PT-2021-18211
8.1
2021-04-13
Unknown · Trestle-Auth · CVE-2021-29435
Name of the Vulnerable Software and Affected Versions: trestle-auth versions 0.4.0 through 0.4.1 Description: A vulnerability in trestle-auth allows an attacker to create a form that will bypass Rails' built-in CSRF protection when submitted by a victim with a trestle-auth admin session. This potentially allows an attacker to alter protected data, including admin account credentials. Recommendations: For versions 0.4.0 and 0.4.1, update to trestle-auth 0.4.2 to fix the vulnerability.