PT-2023-19865 · Rails+1 · Rails+1
Ankane
·
Published
2023-02-02
·
Updated
2025-03-26
·
CVE-2023-25015
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Clockwork Web versions prior to 0.1.2
Rails versions prior to 5.2
Description
The issue allows Cross-Site Request Forgery (CSRF) attacks, which work by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, actions include enabling and disabling jobs.
Recommendations
For Clockwork Web versions prior to 0.1.2, upgrade to version 0.1.2 or later.
For Rails versions prior to 5.2, upgrade to version 5.2 or later.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clockwork Web
Rails