Cross-site Request Forgery (CSRF) Affecting rails_admin package, versions < 1.1.1
Threat Intelligence
EPSS
0.51% (78th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-RAILSADMIN-22043
- published 19 Jul 2018
- disclosed 25 Dec 2016
- credit Unknown
Introduced: 25 Dec 2016
CVE-2016-10522 Open this link in a new tabHow to fix?
Upgrade rails_admin
to version 1.1.1 or higher.
Overview
rails_admin is a Rails engine that provides an easy-to-use interface for managing your data.
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF). An attacker could gain access to the application administrative endpoints exposed by the gem.
References
CVSS Scores
version 3.1