VDB
Sign up
HIGH8.1

GHSA-v6fx-752r-ccp2

PgHero gem allows CSRF

Quick fix

GHSA-v6fx-752r-ccp2 — pghero: upgrade to the fixed version with the command below.

bundle update pghero

Details

The PgHero gem through 2.6.0 for Ruby allows CSRF. PgHero normally uses the `protect_from_forgery` method from Rails to prevent CSRF. However, this defaults to `:null_session`, which has no effect on non-session based authentication methods. Thus the ruby gem is vulnerable with non-session based authentication methods like basic authentication.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/pghero
Introduced in: 0Fixed in: 2.7.0
Fixbundle update pghero

References