Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-12-15 17:30
Updated : 2023-02-12 18:19
NVD link : CVE-2008-7248
Mitre link : CVE-2008-7248
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
rubyonrails
- rails