Skip to content

Commit c1f265c

Browse files
committed
Merge pull request #250 from skorth/add_spina_ruby_gem
Add Spina Ruby Gem
2 parents b08435d + 40127c0 commit c1f265c

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

gems/spina/CVE-2015-4619.yml

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
---
2+
gem: spina
3+
cve: 2015-4619
4+
title: Cross-site request forgery (CSRF) vulnerability in Spina gem
5+
date: 2015-06-16
6+
url: http://www.openwall.com/lists/oss-security/2015/06/16/11
7+
8+
description: >-
9+
`Spina::ApplicationController` actions didn't have CSRF
10+
protection. This causes a CSRF vulnerability across the
11+
entire engine which includes administrative functionality
12+
such as creating users, changing passwords,
13+
and media management.
14+
15+
patched_versions:
16+
- ">= 0.6.29"

0 commit comments

Comments
 (0)