Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-1840

17
FAUCET Score

CVE-2015-1840 describes a Same Origin Policy bypass vulnerability in jquery_ujs.js and rails.js, affecting Ruby on Rails 3.x and 4.x, as well as associated jquery-rails and jquery-ujs versions. An attacker could exploit this by including a leading space in a URL within an attribute, causing a CSRF token to be transmitted to a different-domain server. With a CVSS score of 5.0, this vulnerability has a low attack complexity and allows for information disclosure (CWE-200), specifically the exposure of a CSRF token. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating low current attention.

Impacted Technologies

VendorProductVersion(s)CPE
21CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
22CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
<= 3.1.2CPE matchmatch criteria
cpe:2.3:a:rubyonrails:jquery-rails:*:*:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:rubyonrails:jquery-rails:4.0.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:rubyonrails:jquery-rails:4.0.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.40%
Probability of exploitation in next 30 days
EPSS Percentile
90.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0440 is in the 87th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

rubygemspatch availablevia ghsa
Product: jquery-railsFixed in: 3.1.3
rubygemspatch availablevia ghsa
Product: jquery-railsFixed in: 4.0.4
rubygemspatch availablevia ghsa
Product: jquery-ujsFixed in: 1.0.4
github_advisoryvendor investigatingvia nvd_reference
View patch
redhatno patchvia redhat_api
Product: CloudForms Management Engine 5Fixed in: ruby193-rubygem-jquery-rails
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: ruby193-rubygem-jquery-rails
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-ror41-rubygem-jquery-rails
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: ror40-rubygem-jquery-rails
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: ruby193-rubygem-jquery-rails
redhatend of lifevia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: ruby193-rubygem-jquery-rails

Vendor Advisories (2)

rubygemsGHSA-4whc-pp4x-9pf3medium

jquery-rails and jquery-ujs subject to Exposure of Sensitive Information

Oct 24, 2017
redhatCVE-2015-1840Moderate

rubygem-jquery-rails: CSRF Vulnerability in jquery-ujs and jquery-rails

Jun 16, 2015

References

lists.fedoraproject.org / pipermail/package-announce/2015-June/160906.html
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2015-June/161043.html
Third Party Advisory
lists.opensuse.org / opensuse-updates/2015-07/msg00041.html
Third Party Advisory
openwall.com / lists/oss-security/2015/06/16/15
github.com / rails/jquery-rails/blob/master/CHANGELOG.md
Vendor Advisory
github.com / rails/jquery-ujs/blob/master/CHANGELOG.md
Vendor Advisory
groups.google.com / forum/message/raw
ExploitVendor Advisory
securityfocus.com / bid/75239