VDB
Sign up
HIGH8.8

GHSA-pxqr-8v54-m2hj

Cross-site request forgery in rails_admin

Quick fix

GHSA-pxqr-8v54-m2hj — rails_admin: upgrade to the fixed version with the command below.

bundle update rails_admin

Details

rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rails_admin
Introduced in: 1.0.0Fixed in: 1.1.1
Fixbundle update rails_admin

References