CVE-2020-8167 (Medium) detected in rails-3.0.9.gem
mend-bolt-for-github opened this issue · comments
CVE-2020-8167 - Medium Severity Vulnerability
Vulnerable Library - rails-3.0.9.gem
Ruby on Rails is a full-stack web framework optimized for programmer happiness and sustainable productivity. It encourages beautiful code by favoring convention over configuration.
Library home page: https://rubygems.org/gems/rails-3.0.9.gem
Dependency Hierarchy:
- ❌ rails-3.0.9.gem (Vulnerable Library)
Found in HEAD commit: 0c785fd9400921392b8ee5e3e166f30364359ecc
Found in base branch: master
Vulnerability Details
A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
Publish Date: 2020-06-19
URL: CVE-2020-8167
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://rubygems.org/gems/rails/versions/6.0.3.1
Release Date: 2020-06-01
Fix Resolution: 6.0.3.1,5.2.4.3
Step up your Open Source Security Game with WhiteSource here