PT-2020-19995 · Ruby On Rails+3 · Rails+3
Published
2020-05-26
·
Updated
2025-09-29
·
CVE-2020-8166
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
rails versions prior to 5.2.5
rails versions prior to 6.0.4
Description
A CSRF forgery issue exists that allows an attacker to forge a per-form CSRF token given a global CSRF token, such as the one present in the
authenticity token meta tag. This enables the attacker to construct a per-form CSRF token for any action in that session.Recommendations
For rails versions prior to 5.2.5, update to version 5.2.5 or later.
For rails versions prior to 6.0.4, update to version 6.0.4 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Rails
Red Os
Suse