Bug 1843084 (CVE-2020-8167) - CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs
Summary: CVE-2020-8167 rubygem-actionview: CSRF vulnerability in rails-ujs
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2020-8167
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1842995 1842996 1843085 1846377
Blocks: 1843086
TreeView+ depends on / blocked
 
Reported: 2020-06-02 17:33 UTC by Guilherme de Almeida Suckevicz
Modified: 2021-12-14 18:47 UTC (History)
25 users (show)

Fixed In Version: rubygem-actionview-5.2.4.3, rubygem-actionview-6.0.3.1
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in rubygem-actionview. A regression of CVE-2015-1840 causes Rails-ujs to send CSRF tokens to wrong domains. The highest threat from this vulnerability is to data integrity.
Clone Of:
Environment:
Last Closed: 2021-11-08 18:01:36 UTC


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2020-06-02 17:33:30 UTC
There is an vulnerability in rails-ujs that allows attackers to send CSRF tokens to wrong domains. This is a regression of CVE-2015-1840.

Reference:
https://groups.google.com/forum/#!msg/rubyonrails-security/x9DixQDG9a0/1kX1XubAAQAJ

Comment 1 Guilherme de Almeida Suckevicz 2020-06-02 17:33:48 UTC
Created rubygem-actionview tracking bugs for this issue:

Affects: fedora-all [bug 1843085]

Comment 3 Yadnyawalk Tale 2020-06-03 17:44:45 UTC
External References:

https://groups.google.com/forum/#!topic/rubyonrails-security/x9DixQDG9a0

Comment 4 Yadnyawalk Tale 2020-06-03 17:58:03 UTC
GitHub Commit: https://github.com/rails/rails/commit/a20fbf9bc52e9596a675c1071ab3fe052ac4f0dc


Note You need to log in before you can comment on or make changes to this bug.