CVE-2008-7248
published 2009-12-16CVE-2008-7248: Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass…
PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
8.08%
94.2th percentile
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 2.1.0 < 2.1.3 | 2.1.3 |
| actionpack_project | actionpack | >= 2.2.0 < 2.2.2 | 2.2.2 |
| debian | rails | < rails 2.2.3-1 (bookworm) | rails 2.2.3-1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 2.2.3-1 | 2.2.3-1 |
| rubyonrails | rails | >= 0 < 2.2.3-1 | 2.2.3-1 |
| rubyonrails | rails | >= 0 < 2.2.3-1 | 2.2.3-1 |
| rubyonrails | rails | >= 0 < 2.2.3-1 | 2.2.3-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: Potential CSRF protection circumvention
vendor_redhat·2008-11-18·CVSS 6.8
CVE-2008-7248 [MEDIUM] CWE-352 rubygem-actionpack: Potential CSRF protection circumvention
rubygem-actionpack: Potential CSRF protection circumvention
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
Debian
CVE-2008-7248: rails - Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for...
vendor_debian·2008·CVSS 6.8
CVE-2008-7248 [MEDIUM] CVE-2008-7248: rails - Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for...
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
Scope: local
bookworm: resolved (fixed in 2.2.3-1)
bullseye: resolved (fixed in 2.2.3-1)
forky: resolved (fixed in 2.2.3-1)
sid: resolved (fixed in 2.2.3-1)
trixie: resolved (fixed in 2.2.3-1)
OSV
Improper Input Validation in actionpack
osv·2017-10-24
CVE-2008-7248 [MEDIUM] Improper Input Validation in actionpack
Improper Input Validation in actionpack
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
GHSA
Improper Input Validation in actionpack
ghsa·2017-10-24
CVE-2008-7248 [MEDIUM] CWE-20 Improper Input Validation in actionpack
Improper Input Validation in actionpack
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
OSV
CVE-2008-7248: Ruby on Rails 2
osv·2009-12-16·CVSS 6.8
CVE-2008-7248 [MEDIUM] CVE-2008-7248: Ruby on Rails 2
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
No detection rules found.
http://groups.google.com/group/rubyonrails-security/browse_thread/thread/d741ee286e36e301?hl=enhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://pseudo-flaw.net/content/web-browsers/form-data-encoding-roundup/http://secunia.com/advisories/36600http://secunia.com/advisories/38915http://weblog.rubyonrails.org/2008/11/18/potential-circumvention-of-csrf-protection-in-rails-2-1http://www.openwall.com/lists/oss-security/2009/11/28/1http://www.openwall.com/lists/oss-security/2009/12/02/2http://www.rorsecurity.info/journal/2008/11/19/circumvent-rails-csrf-protection.htmlhttp://www.vupen.com/english/advisories/2009/2544http://groups.google.com/group/rubyonrails-security/browse_thread/thread/d741ee286e36e301?hl=enhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://pseudo-flaw.net/content/web-browsers/form-data-encoding-roundup/http://secunia.com/advisories/36600http://secunia.com/advisories/38915http://weblog.rubyonrails.org/2008/11/18/potential-circumvention-of-csrf-protection-in-rails-2-1http://www.openwall.com/lists/oss-security/2009/11/28/1http://www.openwall.com/lists/oss-security/2009/12/02/2http://www.rorsecurity.info/journal/2008/11/19/circumvent-rails-csrf-protection.htmlhttp://www.vupen.com/english/advisories/2009/2544
2009-12-16
Published