CVE-2008-7248 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 8.1% (pctl 95)
Patch early
A public exploit exists.
Description
Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 8.08% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-12-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| rubyonrails | rails |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ruby on Rails 2.3.5 - 'protect_from_forgery' Cross-Site Request Forgery | 2009-12-14 |
References
- http://groups.google.com/group/rubyonrails-security/browse_thread/thread/d741ee286e36e301?hl=en
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
- http://pseudo-flaw.net/content/web-browsers/form-data-encoding-roundup/
- http://secunia.com/advisories/36600
- http://secunia.com/advisories/38915
- http://weblog.rubyonrails.org/2008/11/18/potential-circumvention-of-csrf-protection-in-rails-2-1
- http://www.openwall.com/lists/oss-security/2009/11/28/1
- http://www.openwall.com/lists/oss-security/2009/12/02/2
- http://www.rorsecurity.info/journal/2008/11/19/circumvent-rails-csrf-protection.html
- http://www.vupen.com/english/advisories/2009/2544
- http://groups.google.com/group/rubyonrails-security/browse_thread/thread/d741ee286e36e301?hl=en
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
- http://pseudo-flaw.net/content/web-browsers/form-data-encoding-roundup/
- http://secunia.com/advisories/36600
- http://secunia.com/advisories/38915
- http://weblog.rubyonrails.org/2008/11/18/potential-circumvention-of-csrf-protection-in-rails-2-1
- http://www.openwall.com/lists/oss-security/2009/11/28/1
- http://www.openwall.com/lists/oss-security/2009/12/02/2
- http://www.rorsecurity.info/journal/2008/11/19/circumvent-rails-csrf-protection.html
- http://www.vupen.com/english/advisories/2009/2544
→ the Explorer · watch your stack · NVD