Back

MEDIUM

rubygem-actionpack: ability to forge per-form CSRF tokens given a global CSRF token

Published Jul 2, 2020

Description

A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Jul 2, 2020
Updated Apr 28, 2026
Reserved Jan 28, 2020
CISA Vulnrichment
Updated Apr 28, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 18, 2020
GHSA-JP5V-5GX4-JMJ9