摘要:
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
安全等级: Low
公告ID: KylinSec-SA-2022-1204
发布日期: 2022年11月18日
关联CVE: CVE-2020-8166
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2020-8166 | KY3.4-4A | rubygem-rails | Unaffected |
CVE-2020-8166 | KY3.4-5 | rubygem-rails | Unaffected |
CVE-2020-8166 | KY3.5.1 | rubygem-rails | Unaffected |