CVE-2011-0447
Publication date 14 February 2011
Last updated 24 July 2024
Ubuntu priority
Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage “combinations of browser plugins and HTTP redirects,” a related issue to CVE-2011-0696.
Status
Package | Ubuntu Release | Status |
---|---|---|
rails | 11.04 natty |
Fixed 2.3.5-1.2ubuntu1.1
|
10.10 maverick |
Fixed 2.3.5-1.1ubuntu0.1
|
|
10.04 LTS lucid |
Fixed 2.2.3-2ubuntu0.1
|
|
9.10 karmic | Ignored end of life | |
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life |