Ruby on Rails 'protect_from_forgery' Cross Site Request Forgery Vulnerability
BID:37322
Info
Ruby on Rails 'protect_from_forgery' Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 37322 |
| Class: | Design Error |
| CVE: |
CVE-2008-7248 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2009 12:00AM |
| Updated: | Mar 15 2010 04:32PM |
| Credit: | p0deje |
| Vulnerable: |
SuSE SUSE Linux Enterprise 10 SP3 SuSE SUSE Linux Enterprise 10 SP2 S.u.S.E. openSUSE 11.1 Ruby on Rails Ruby on Rails 2.3.5 Ruby on Rails Ruby on Rails 2.3.4 Ruby on Rails Ruby on Rails 2.3.3 Ruby on Rails Ruby on Rails 2.3.2 Ruby on Rails Ruby on Rails 2.2.3 Ruby on Rails Ruby on Rails 2.2.2 Ruby on Rails Ruby on Rails 2.1.1 Ruby on Rails Ruby on Rails 2.1 Ruby on Rails Ruby on Rails 2.0.5 Ruby on Rails Ruby on Rails 2.0.4 Ruby on Rails Ruby on Rails 2.0 Ruby on Rails Ruby on Rails 1.2.6 Ruby on Rails Ruby on Rails 1.2.5 Ruby on Rails Ruby on Rails 1.2.3 Ruby on Rails Ruby on Rails 1.1.6 Ruby on Rails Ruby on Rails 1.1.5 Ruby on Rails Ruby on Rails 1.1.4 Ruby on Rails Ruby on Rails 1.1.3 Ruby on Rails Ruby on Rails 1.1.2 Ruby on Rails Ruby on Rails 1.1.1 Ruby on Rails Ruby on Rails 1.1 Ruby on Rails Ruby on Rails 1.0 Ruby on Rails Ruby on Rails 0.14 Ruby on Rails Ruby on Rails 0.13 Redmine Redmine 0.8.7 Redmine Redmine 0.8.6 Redmine Redmine 0.8.5 Redmine Redmine 0.7.3 Redmine Redmine 0.7.2 |
| Not Vulnerable: | |
Discussion
Ruby on Rails 'protect_from_forgery' Cross Site Request Forgery Vulnerability
Ruby on Rails is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, or delete certain data. Other attacks are also possible.
Ruby on Rails is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions, gain unauthorized access to the affected application, or delete certain data. Other attacks are also possible.
Exploit / POC
Ruby on Rails 'protect_from_forgery' Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example code is available for leveraging this issue on Redmine:
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example code is available for leveraging this issue on Redmine:
Solution / Fix
Ruby on Rails 'protect_from_forgery' Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Ruby on Rails 'protect_from_forgery' Cross Site Request Forgery Vulnerability
References:
References:
- Redmine Homepage (Redmine)
- Ruby on Rails Homepage (Ruby on Rails)