HIGH8.1
GHSA-v6fx-752r-ccp2
PgHero gem allows CSRF
Quick fix
GHSA-v6fx-752r-ccp2 — pghero: upgrade to the fixed version with the command below.
bundle update pgheroDetails
The PgHero gem through 2.6.0 for Ruby allows CSRF. PgHero normally uses the `protect_from_forgery` method from Rails to prevent CSRF. However, this defaults to `:null_session`, which has no effect on non-session based authentication methods. Thus the ruby gem is vulnerable with non-session based authentication methods like basic authentication.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-16253[ADVISORY]
- https://github.com/ankane/pghero/issues/330[WEB]
- https://github.com/ankane/pghero/commit/14b67b32fed19a30aaf9826ee72f2a29cda604e9[WEB]
- https://github.com/ankane/pghero[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/pghero/CVE-2020-16253.yml[WEB]