Description
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0419 | rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem. |
Github GHSA |
GHSA-pxqr-8v54-m2hj | Cross-site request forgery in rails_admin |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-06T03:21:52.174Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2016-10522
No data.
Status : Modified
Published: 2018-07-05T16:29:00.250
Modified: 2024-11-21T02:44:11.737
Link: CVE-2016-10522
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA