CVE-2020-8166
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
- Rubyonrails Rails
- < 5.2.4.3, 6.0.3.1
- Fix
- Available
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2020-07-02
CVE-2020-8166 at NVD
No indexed exploits for CVE-2020-8166 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-8166 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.