VDB
Sign up
MEDIUM

GHSA-8fqx-7pv4-3jwm

Improper Input Validation in actionpack

Quick fix

GHSA-8fqx-7pv4-3jwm — actionpack: upgrade to the fixed version with the command below.

bundle update actionpack

Details

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/actionpack
Introduced in: 2.1.0Fixed in: 2.1.3
Fixbundle update actionpack
RubyGems/actionpack
Introduced in: 2.2.0Fixed in: 2.2.2
Fixbundle update actionpack

References