CVE-2008-7248: Input Validation

Published Nov 18, 2008
·
Updated

A possibility to circumvent protection against cross-site request forgery (CSRF) attacks was found in Ruby on Rails. Quoting upstream security advisory for exact details:

There is a bug in all 2.1.x versions of Ruby on Rails which affects the effectiveness of the CSRF protection given by protectfromforgery.

By design rails does not perform token verification on requests with certain content types not typically generated by browsers. Unfortunately this list also included ‘text/plain’ which can be generated by browsers.

Requests can be crafted which will circumvent the CSRF protection entirely. Rails does not parse the parameters provided with these requests, but that may not be enough to protect your application.

References: ----------- http://www.rorsecurity.info/journal/2008/11/19/circumvent-rails-csrf-protection.html http://weblog.rubyonrails.org/2008/11/18/potential-circumvention-of-csrf-protection-in-rails-2-1

Upstream patch: --------------- http://github.com/rails/rails/commit/099a98e9b7108dae3e0f78b207e0a7dc5913bd1a

CVE Request: ------------ http://www.openwall.com/lists/oss-security/2009/11/28/1

Other sources

Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

Affected Software

7 affected componentsFixes available
rubygems/actionpack>=2.2.0<2.2.2
2.2.2
rubygems/actionpack>=2.1.0<2.1.3
2.1.3
rubyonrails Rails=2.1.0
rubyonrails Rails=2.1.1
rubyonrails Rails=2.1.2
rubyonrails Rails=2.2.0
rubyonrails Rails=2.2.1

Event History

Nov 18, 2008
CVE Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionSeverityWeakness
Dec 4, 2009
Data Sourced
via Red Hat·04:12 PM
Affected Software
Dec 16, 2009
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Oct 24, 2017
Advisory Published
06:33 PM

Frequently Asked Questions

1

What is the severity of CVE-2008-7248?

CVE-2008-7248 is considered to be a medium severity vulnerability due to its potential to allow cross-site request forgery attacks.

2

How do I fix CVE-2008-7248?

To fix CVE-2008-7248, upgrade to Ruby on Rails versions 2.1.3 or 2.2.2 or higher.

3

Which versions of Ruby on Rails are affected by CVE-2008-7248?

Versions 2.1.0, 2.1.1, 2.1.2, 2.2.0, and 2.2.1 of Ruby on Rails are affected by CVE-2008-7248.

4

What type of attacks can CVE-2008-7248 potentially allow?

CVE-2008-7248 can potentially allow attackers to exploit cross-site request forgery (CSRF) vulnerabilities.

5

Is CVE-2008-7248 associated with any specific software packages?

Yes, CVE-2008-7248 is specifically associated with the Ruby on Rails framework, particularly the actionpack package.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203