VDB
Sign up
MEDIUM4.3

GHSA-jp5v-5gx4-jmj9

Ability to forge per-form CSRF tokens in Rails

Quick fix

GHSA-jp5v-5gx4-jmj9 — actionpack: upgrade to the fixed version with the command below.

bundle update actionpack

Details

It is possible to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token for any action for that session.

Impact ------

Given the ability to extract the global CSRF token, an attacker would be able to construct a per-form CSRF token for that session.

Workarounds -----------

This is a low-severity security issue. As such, no workaround is necessarily until such time as the application can be upgraded.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/actionpack
Introduced in: 5.0.0Fixed in: 5.2.4.3
Fixbundle update actionpack
RubyGems/actionpack
Introduced in: 6.0.0Fixed in: 6.0.3.1
Fixbundle update actionpack

References