cbcvebase.
CVE-2015-1840
published 2015-07-26

CVE-2015-1840: jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote…

PriorityP428medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.40%
90.2th percentile
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianruby-jquery-rails< ruby-jquery-rails 4.0.4-1 (bookworm)ruby-jquery-rails 4.0.4-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
opensuseopensuse
opensuseopensuse
railsactionview>= 5.0.0 < 5.2.4.35.2.4.3
railsactionview>= 6.0.0 < 6.0.3.16.0.3.1
rubyonrailsjquery-rails<= 3.1.2
rubyonrailsjquery-rails
rubyonrailsjquery-rails
rubyonrailsjquery-rails>= 0 < 3.1.33.1.3
rubyonrailsjquery-rails>= 4.0.0 < 4.0.44.0.4
rubyonrailsjquery-ujs<= 1.0.3
rubyonrailsjquery-ujs>= 0 < 1.0.41.0.4

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.