Cross-site request forgery in ActionView - CVE-2020-8167

 

Cross-site request forgery in ActionView - CVE-2020-8167

Published: May 26, 2020


Vulnerability identifier: #VU28241
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8167
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.

This is a regression of CVE-2015-1840.


Affected software

ActionView
SUSE Linux Enterprise High Availability Extension 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Server 15 SP1 Business Critical Linux
SUSE Linux Enterprise Server 15 SP2 Business Critical Linux
SUSE Linux Enterprise Server 15 SP3 Business Critical Linux
openSUSE Leap
rails (Debian package)
ruby2.5-rubygem-actionview-5_1
ruby2.5-rubygem-actionview-doc-5_1

How to mitigate CVE-2020-8167

Install updates from vendor's website.

ActionView - addressed in versions 5.2.4.3, 6.0.3.1
rails (Debian package) - update to 5.2.2.1+dfsg-1+deb10u2
ruby2.5-rubygem-actionview-5_1 - update to 5.1.4-150000.3.6.1
ruby2.5-rubygem-actionview-doc-5_1 - update to 5.1.4-150000.3.6.1

External References

Related Security Bulletins