VDB
KO
MEDIUM

GHSA-8fqx-7pv4-3jwm

Improper Input Validation in actionpack

Details

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / actionpack
Introduced in: 2.1.0 Fixed in: 2.1.3
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 2.2.0 Fixed in: 2.2.2
Fix bundle update actionpack

References