Medium severity4.3NVD Advisory· Published Jul 2, 2020· Updated Apr 28, 2026
CVE-2020-8166
CVE-2020-8166
Description
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
actionpackRubyGems | >= 5.0.0, < 5.2.4.3 | 5.2.4.3 |
actionpackRubyGems | >= 6.0.0, < 6.0.3.1 | 6.0.3.1 |
Affected products
22- ghsa-coords20 versionspkg:gem/actionpackpkg:rpm/opensuse/rmt-server&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/rmt-server&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/rmt-server&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rubygem-actionpack-5_1&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/rubygem-actionpack-5_1&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/rubygem-actionpack-6.0&distro=openSUSE%20Tumbleweedpkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP1pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP2pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2pkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/rmt-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/rubygem-actionpack-5_1&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1pkg:rpm/suse/rubygem-actionpack-5_1&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP2pkg:rpm/suse/rubygem-actionpack-5_1&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP3pkg:rpm/suse/rubygem-actionpack-5_1&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP4pkg:rpm/suse/rubygem-actionpack-5_1&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP5
>= 5.0.0, < 5.2.4.3+ 19 more
- (no CPE)range: >= 5.0.0, < 5.2.4.3
- (no CPE)range: < 2.6.5-lp151.2.18.2
- (no CPE)range: < 2.6.5-lp152.2.3.1
- (no CPE)range: < 2.6.13-1.1
- (no CPE)range: < 5.1.4-150000.3.29.1
- (no CPE)range: < 5.1.4-150000.3.29.1
- (no CPE)range: < 6.0.4.4-1.1
- (no CPE)range: < 2.6.5-3.34.1
- (no CPE)range: < 2.6.5-3.34.1
- (no CPE)range: < 2.6.5-3.18.1
- (no CPE)range: < 2.6.5-3.3.1
- (no CPE)range: < 2.6.5-3.18.1
- (no CPE)range: < 2.6.5-3.3.1
- (no CPE)range: < 2.6.5-3.34.1
- (no CPE)range: < 2.6.5-3.34.1
- (no CPE)range: < 5.1.4-150000.3.29.1
- (no CPE)range: < 5.1.4-150000.3.29.1
- (no CPE)range: < 5.1.4-150000.3.29.1
- (no CPE)range: < 5.1.4-150000.3.29.1
- (no CPE)range: < 5.1.4-150000.3.29.1
Patches
Vulnerability mechanics
References
7- groups.google.com/g/rubyonrails-security/c/NOjKiGeXUgwnvdMailing ListPatchThird Party AdvisoryWEB
- hackerone.com/reports/732415nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jp5v-5gx4-jmj9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-8166ghsaADVISORY
- www.debian.org/security/2020/dsa-4766nvdThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2020-8166.ymlghsaWEB
- groups.google.com/forum/ghsaWEB
News mentions
0No linked articles in our index yet.