PT-2009-2715 · Ruby · Ruby On Rails

Alex Legler

·

Published

2009-12-16

·

Updated

2023-02-13

·

CVE-2008-7248

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 2.1 through 2.1.3 and versions 2.2.x through 2.2.2
Description The issue allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection. This is possible because Ruby on Rails does not verify tokens for requests with certain content types, as demonstrated using text/plain.
Recommendations For versions 2.1 through 2.1.3, update to version 2.1.3 or later to resolve the issue. For versions 2.2.x through 2.2.2, update to version 2.2.2 or later to resolve the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7248
GHSA-8FQX-7PV4-3JWM

Affected Products

Ruby On Rails