Bug 1843084 (CVE-2020-8167)

Summary: CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs
Product: [Other] Security Response Reporter: Guilherme de Almeida Suckevicz <gsuckevi>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akarol, bbuckingham, bcourt, bkearney, bmidwood, btotty, dmetzger, gmccullo, gtanzill, hhudgeon, jaruga, jhardy, lzap, mmccune, nmoumoul, pvalena, rchan, rjerrido, roliveri, ruby-packagers-sig, simaishi, smallamp, sokeeffe, strzibny, xlecauch
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: rubygem-actionview-5.2.4.3, rubygem-actionview-6.0.3.1 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in rubygem-actionview. A regression of CVE-2015-1840 causes Rails-ujs to send CSRF tokens to wrong domains. The highest threat from this vulnerability is to data integrity.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-11-08 18:01:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1842995, 1842996, 1843085, 1846377    
Bug Blocks: 1843086    

Description Guilherme de Almeida Suckevicz 2020-06-02 17:33:30 UTC
There is an vulnerability in rails-ujs that allows attackers to send CSRF tokens to wrong domains. This is a regression of CVE-2015-1840.

Reference:
https://groups.google.com/forum/#!msg/rubyonrails-security/x9DixQDG9a0/1kX1XubAAQAJ

Comment 1 Guilherme de Almeida Suckevicz 2020-06-02 17:33:48 UTC
Created rubygem-actionview tracking bugs for this issue:

Affects: fedora-all [bug 1843085]

Comment 3 Yadnyawalk Tale 2020-06-03 17:44:45 UTC
External References:

https://groups.google.com/forum/#!topic/rubyonrails-security/x9DixQDG9a0

Comment 4 Yadnyawalk Tale 2020-06-03 17:58:03 UTC
GitHub Commit: https://github.com/rails/rails/commit/a20fbf9bc52e9596a675c1071ab3fe052ac4f0dc