PT-2023-19865 · Rails+1 · Rails+1

Ankane

·

Published

2023-02-02

·

Updated

2025-03-26

·

CVE-2023-25015

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Clockwork Web versions prior to 0.1.2 Rails versions prior to 5.2
Description The issue allows Cross-Site Request Forgery (CSRF) attacks, which work by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, actions include enabling and disabling jobs.
Recommendations For Clockwork Web versions prior to 0.1.2, upgrade to version 0.1.2 or later. For Rails versions prior to 5.2, upgrade to version 5.2 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-25015
GHSA-P4XX-W6FR-C4W9

Affected Products

Clockwork Web
Rails