Description
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2008-0344 Vulnerability (CVE-2008-0344)
WordPress Plugin Simple:Press-WordPress Forum Arbitrary File Upload (6.6.0)
WordPress Plugin Email Queue by BestWebSoft Cross-Site Scripting (1.1.1)
Joomla! Core 1.6.0 Multiple Vulnerabilities (1.6.0)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-1856)