VDB
Sign up
MEDIUM5.4

GHSA-cc8c-26rj-v2vx

administrate vulnerable to Cross-Site Request Forgery

Quick fix

GHSA-cc8c-26rj-v2vx — administrate: upgrade to the fixed version with the command below.

bundle update administrate

Details

Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/administrate
Introduced in: 0Fixed in: 0.1.5
Fixbundle update administrate

References