CVE-2020-8167
published 2020-06-19CVE-2020-8167: A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
1.49%
71.1th percentile
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | rails | < rails 2:5.2.4.3+dfsg-1 (bookworm) | rails 2:5.2.4.3+dfsg-1 (bookworm) |
| http | github.com_rails_rails | — | — |
| rails | actionview | >= 5.0.0 < 5.2.4.3 | 5.2.4.3 |
| rails | actionview | >= 6.0.0 < 6.0.3.1 | 6.0.3.1 |
| rubyonrails | rails | < 5.2.4.3 | 5.2.4.3 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:5.2.4.3+dfsg-1 | 2:5.2.4.3+dfsg-1 |
| rubyonrails | rails | >= 6.0.0 < 6.0.3.1 | 6.0.3.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.0MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CSRF Vulnerability in rails-ujs
osv·2020-07-07·CVSS 5.0
CVE-2020-8167 [MEDIUM] CSRF Vulnerability in rails-ujs
CSRF Vulnerability in rails-ujs
There is a vulnerability in rails-ujs that allows attackers to send CSRF tokens to wrong domains.
Versions Affected: rails = 5.2.4.3, rails >= 6.0.3.1
Impact
This is a regression of CVE-2015-1840.
In the scenario where an attacker might be able to control the href attribute of an anchor tag or the action attribute of a form tag that will trigger a POST action, the attacker can set the href or action to a cross-origin URL, and the CSRF token will be sent.
Workarounds
To work around this problem, change code that allows users to control the href attribute of an anchor tag or the action attribute of a form tag to filter the user parameters.
For example, code like this:
link_to params
to code like this:
link_to filtered_params
def filtered_params
# F
GHSA
CSRF Vulnerability in rails-ujs
ghsa·2020-07-07·CVSS 5.0
CVE-2020-8167 [MEDIUM] CWE-352 CSRF Vulnerability in rails-ujs
CSRF Vulnerability in rails-ujs
There is a vulnerability in rails-ujs that allows attackers to send CSRF tokens to wrong domains.
Versions Affected: rails = 5.2.4.3, rails >= 6.0.3.1
Impact
This is a regression of CVE-2015-1840.
In the scenario where an attacker might be able to control the href attribute of an anchor tag or the action attribute of a form tag that will trigger a POST action, the attacker can set the href or action to a cross-origin URL, and the CSRF token will be sent.
Workarounds
To work around this problem, change code that allows users to control the href attribute of an anchor tag or the action attribute of a form tag to filter the user parameters.
For example, code like this:
link_to params
to code like this:
link_to filtered_params
def filtered_params
# F
OSV
CVE-2020-8167: A CSRF vulnerability exists in rails <= 6
osv·2020-06-19·CVSS 6.5
CVE-2020-8167 [MEDIUM] CVE-2020-8167: A CSRF vulnerability exists in rails <= 6
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
Red Hat
rubygem-actionview: CSRF vulnerability in rails-ujs
vendor_redhat·2020-05-18·CVSS 5.0
CVE-2020-8167 [MEDIUM] CWE-352 rubygem-actionview: CSRF vulnerability in rails-ujs
rubygem-actionview: CSRF vulnerability in rails-ujs
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
A flaw was found in rubygem-actionview. A regression of CVE-2015-1840 causes Rails-ujs to send CSRF tokens to wrong domains. The highest threat from this vulnerability is to data integrity.
Package: cfme-amazon-smartstate (CloudForms Management Engine 5) - Not affected
Package: cfme-gemset (CloudForms Management Engine 5) - Will not fix
Debian
CVE-2020-8167: rails - A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow ...
vendor_debian·2020·CVSS 6.5
CVE-2020-8167 [MEDIUM] CVE-2020-8167: rails - A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow ...
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
Scope: local
bookworm: resolved (fixed in 2:5.2.4.3+dfsg-1)
bullseye: resolved (fixed in 2:5.2.4.3+dfsg-1)
forky: resolved (fixed in 2:5.2.4.3+dfsg-1)
sid: resolved (fixed in 2:5.2.4.3+dfsg-1)
trixie: resolved (fixed in 2:5.2.4.3+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs
bugzilla·2020-06-02·CVSS 5.0
CVE-2020-8167 [MEDIUM] CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs
CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs
There is an vulnerability in rails-ujs that allows attackers to send CSRF tokens to wrong domains. This is a regression of CVE-2015-1840.
Reference:
https://groups.google.com/forum/#!msg/rubyonrails-security/x9DixQDG9a0/1kX1XubAAQAJ
Discussion:
Created rubygem-actionview tracking bugs for this issue:
Affects: fedora-all [bug 1843085]
---
External References:
https://groups.google.com/forum/#!topic/rubyonrails-security/x9DixQDG9a0
---
GitHub Commit: https://github.com/rails/rails/commit/a20fbf9bc52e9596a675c1071ab3fe052ac4f0dc
Bugzilla
CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs [fedora-all]
bugzilla·2020-06-02·CVSS 6.5
CVE-2020-8167 [MEDIUM] CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs [fedora-all]
CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
2020-06-19
Published