Cross-site request forgery in rails_admin
High severity
GitHub Reviewed
Published
Aug 8, 2018
to the GitHub Advisory Database
•
Updated Nov 8, 2023
Description
Published by the National Vulnerability Database
Jul 5, 2018
Published to the GitHub Advisory Database
Aug 8, 2018
Reviewed
Jun 16, 2020
Last updated
Nov 8, 2023
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.
References