CVE-2015-1840 describes a Same Origin Policy bypass vulnerability in jquery_ujs.js and rails.js, affecting Ruby on Rails 3.x and 4.x, as well as associated jquery-rails and jquery-ujs versions. An attacker could exploit this by including a leading space in a URL within an attribute, causing a CSRF token to be transmitted to a different-domain server. With a CVSS score of 5.0, this vulnerability has a low attack complexity and allows for information disclosure (CWE-200), specifically the exposure of a CSRF token. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* | ||
<= 3.1.2CPE matchmatch criteria | cpe:2.3:a:rubyonrails:jquery-rails:*:*:*:*:*:*:*:* | ||
4.0.0CPE matchmatch criteria | cpe:2.3:a:rubyonrails:jquery-rails:4.0.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:jquery-rails:4.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.