cbcvebase.
CVE-2008-7248
published 2009-12-16

CVE-2008-7248: Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass…

PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
8.08%
94.2th percentile
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

Affected

12 ranges
VendorProductVersion rangeFixed in
actionpack_projectactionpack>= 2.1.0 < 2.1.32.1.3
actionpack_projectactionpack>= 2.2.0 < 2.2.22.2.2
debianrails< rails 2.2.3-1 (bookworm)rails 2.2.3-1 (bookworm)
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails>= 0 < 2.2.3-12.2.3-1
rubyonrailsrails>= 0 < 2.2.3-12.2.3-1
rubyonrailsrails>= 0 < 2.2.3-12.2.3-1
rubyonrailsrails>= 0 < 2.2.3-12.2.3-1

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.