CVE-2020-8166: CSRF
Published Jul 2, 2020
·Updated
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticitytoken meta tag, forge a per-form CSRF token.
Affected Software
4 affected componentsFixes available
debian/rails
2:5.2.2.1+dfsg-1+deb10u32:5.2.2.1+dfsg-1+deb10u52:6.0.3.7+dfsg-2+deb11u22:6.1.7.3+dfsg-12:6.1.7.3+dfsg-2
rubyonrails Rails<5.2.4.3
rubyonrails Rails>=6.0.0<6.0.3.1
Debian Debian Linux=10.0
Remediation
Event History
Jul 2, 2020
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-8166.
2
What is the severity of CVE-2020-8166?
The severity of CVE-2020-8166 is not specified.
3
Which software versions are affected by CVE-2020-8166?
The software versions affected by CVE-2020-8166 are rails < 5.2.5 and rails < 6.0.4.
4
How does the CSRF forgery vulnerability in CVE-2020-8166 work?
The CSRF forgery vulnerability in CVE-2020-8166 allows an attacker to forge a per-form CSRF token using a global CSRF token.
5
How can I fix the CSRF forgery vulnerability in rails?
To fix the CSRF forgery vulnerability in rails, update to version 5.2.5 or 6.0.4 or higher.