Back to search
CVE-2008-7248
Published: Dec 16, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20091128 CVE request: Ruby on Rails: CSRF circumvention (from 2008)
mailing-list
x_refsource_MLIST
36600
third-party-advisory
x_refsource_SECUNIA
ADV-2009-2544
vdb-entry
x_refsource_VUPEN
SUSE-SR:2010:006
vendor-advisory
x_refsource_SUSE
[oss-security] 20091202 Re: CVE request: Ruby on Rails: CSRF circumvention (from 2008)
mailing-list
x_refsource_MLIST
38915
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now