Hide Forgot
There is an vulnerability in rails-ujs that allows attackers to send CSRF tokens to wrong domains. This is a regression of CVE-2015-1840. Reference: https://groups.google.com/forum/#!msg/rubyonrails-security/x9DixQDG9a0/1kX1XubAAQAJ
Created rubygem-actionview tracking bugs for this issue: Affects: fedora-all [bug 1843085]
External References: https://groups.google.com/forum/#!topic/rubyonrails-security/x9DixQDG9a0
GitHub Commit: https://github.com/rails/rails/commit/a20fbf9bc52e9596a675c1071ab3fe052ac4f0dc