A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| actionview(RubyGems) | 5.0.0 | 5.2.4.3 | N/A |
| actionview(RubyGems) | 6.0.0 | 6.0.3.1 | N/A |
CVSS Metrics