Skip to content

Commit

Permalink
Added CVE-2023-25015 for clockwork_web
Browse files Browse the repository at this point in the history
  • Loading branch information
ankane authored and postmodern committed Feb 2, 2023
1 parent 04cb4e2 commit 8207385
Showing 1 changed file with 14 additions and 0 deletions.
14 changes: 14 additions & 0 deletions gems/clockwork_web/CVE-2023-25015.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
gem: clockwork_web
cve: 2023-25015
url: https://github.com/ankane/clockwork_web/issues/4
title: CSRF Vulnerability with Rails < 5.2
date: 2023-02-01
description: |
Clockwork Web is vulnerable to cross-site request forgery (CSRF) with Rails < 5.2.
A CSRF attack works by getting an authorized user to visit a malicious website and
then performing requests on behalf of the user. In this instance, actions include
enabling and disabling jobs.
patched_versions:
- ">= 0.1.2"

0 comments on commit 8207385

Please sign in to comment.