CVE-2020-8166 — Cross-Site Request Forgery in Rails
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 2
Description
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages4 packages
Also affects: Debian Linux 10.0