Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 RubyGems

Ability to forge per-form CSRF tokens in Rails

GHSA-jp5v-5gx4-jmj9 · CVE-2020-8166

Published · Modified

Description

It is possible to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token for any action for that session.

Impact

Given the ability to extract the global CSRF token, an attacker would be able to construct a per-form CSRF token for that session.

Workarounds

This is a low-severity security issue. As such, no workaround is necessarily until such time as the application can be upgraded.

Ready to move

Start Securing

Free, no credit card | First findings in minutes