CVE-2020-8166
published 2020-07-02CVE-2020-8166: A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
1.67%
74.2th percentile
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 5.0.0 < 5.2.4.3 | 5.2.4.3 |
| actionpack_project | actionpack | >= 6.0.0 < 6.0.3.1 | 6.0.3.1 |
| debian | debian_linux | — | — |
| debian | rails | < rails 2:5.2.4.3+dfsg-1 (bookworm) | rails 2:5.2.4.3+dfsg-1 (bookworm) |
| https | github.com_rails_rails | — | — |
| rubyonrails | rails | < 5.2.4.3 | 5.2.4.3 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 6.0.0 < 6.0.3.1 | 6.0.3.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-8166: A CSRF forgery vulnerability exists in rails < 5
osv·2020-07-02·CVSS 4.3
CVE-2020-8166 [MEDIUM] CVE-2020-8166: A CSRF forgery vulnerability exists in rails < 5
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
GHSA
Ability to forge per-form CSRF tokens in Rails
ghsa·2020-05-26
CVE-2020-8166 [MEDIUM] CWE-352 Ability to forge per-form CSRF tokens in Rails
Ability to forge per-form CSRF tokens in Rails
It is possible to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token for any action for that session.
Impact
Given the ability to extract the global CSRF token, an attacker would be able to construct a per-form CSRF token for that session.
Workarounds
This is a low-severity security issue. As such, no workaround is necessarily until such time as the application can be upgraded.
OSV
Ability to forge per-form CSRF tokens in Rails
osv·2020-05-26
CVE-2020-8166 [MEDIUM] Ability to forge per-form CSRF tokens in Rails
Ability to forge per-form CSRF tokens in Rails
It is possible to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token for any action for that session.
Impact
Given the ability to extract the global CSRF token, an attacker would be able to construct a per-form CSRF token for that session.
Workarounds
This is a low-severity security issue. As such, no workaround is necessarily until such time as the application can be upgraded.
Red Hat
rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token
vendor_redhat·2020-05-18·CVSS 4.3
CVE-2020-8166 [MEDIUM] CWE-352 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token
rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
A flaw was found in rubygem-actionpack. Forgery of a per-form CSRF token is possible allowing for any action to take place for that session. The highest threat from this vulnerability is to data integrity.
Package: cfme-amazon-smartstate (CloudForms Management Engine 5) - Not affected
Package: cfme-gemset (CloudForms Management Engine 5) - Will not fix
Debian
CVE-2020-8166: rails - A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes i...
vendor_debian·2020·CVSS 4.3
CVE-2020-8166 [MEDIUM] CVE-2020-8166: rails - A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes i...
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
Scope: local
bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1)
bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1)
forky: resolved (fixed in 2:5.2.4.3+dfsg-1)
sid: resolved (fixed in 2:5.2.4.3+dfsg-1)
trixie: resolved (fixed in 2:5.2.4.3+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8166 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token [fedora-all]
bugzilla·2020-06-02·CVSS 4.3
CVE-2020-8166 [MEDIUM] CVE-2020-8166 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token [fedora-all]
CVE-2020-8166 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2020-8166 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token
bugzilla·2020-06-02·CVSS 4.3
CVE-2020-8166 [MEDIUM] CVE-2020-8166 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token
CVE-2020-8166 rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token
It is possible to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token for any action for that session.
Reference:
https://groups.google.com/forum/#!msg/rubyonrails-security/NOjKiGeXUgw/XD3_jtvAAQAJ
Discussion:
Created rubygem-actionpack tracking bugs for this issue:
Affects: fedora-all [bug 1843153]
---
GitHub Commit: https://github.com/rails/rails/commit/d124f19287f4892c72ca54da728a781591c6fca1
arXiv
On the Effectiveness of Clone Detection for Detecting IoT-related Vulnerable Clones
arxiv_fulltext·2021-10-20
On the Effectiveness of Clone Detection for Detecting IoT-related Vulnerable Clones
On the Effectiveness of Clone Detection for Detecting IoT-related Vulnerable Clones
Kentaro Ohno,
Norihiro Yoshida,
Wenqing Zhu
and Hiroaki Takada
Nagoya University, Japan
\k_ohno, yoshida, zhuwqing1995, hiro\@ertl.jp
## Abstract
Since IoT systems provide services over the Internet, they must continue to operate safely even if malicious users attack them.
Since the computational resources of edge devices connected to the IoT are limited, lightweight platforms and network protocols are often used.
Lightweight platforms and network protocols are less resistant to attacks, increasing the risk that developers will embed vulnerabilities.
The code clone research community has been developing approaches to fix buggy (e.g., vulnerable) clones simultaneously. However, there has been little rese
https://groups.google.com/g/rubyonrails-security/c/NOjKiGeXUgwhttps://hackerone.com/reports/732415https://www.debian.org/security/2020/dsa-4766https://groups.google.com/g/rubyonrails-security/c/NOjKiGeXUgwhttps://hackerone.com/reports/732415https://www.debian.org/security/2020/dsa-4766https://hackerone.com/reports/732415
2020-07-02
Published