{"id":"GHSA-wj5j-xpcj-45gc","summary":"Cross-Site Request Forgery (CSRF)","details":"# Withdrawn\n\nAffected versions of the package are vulnerable to Cross-Site Request Forgery (CSRF) attacks.","modified":"2024-12-01T05:31:24.290677Z","published":"2021-02-24T19:17:37Z","withdrawn":"2021-02-24T19:17:37Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2019-06-26T01:06:20Z","nvd_published_at":null,"cwe_ids":["CWE-352"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/scambra/devise_invitable/issues/457"},{"type":"WEB","url":"https://github.com/scambra/devise_invitable/commit/d1bb19efca8e35885e1c2f0931d6171fce8cf74e"},{"type":"WEB","url":"https://www.sourceclear.com/vulnerability-database/security/cross-site-request-forgery-csrf/ruby/sid-2272"}],"affected":[{"package":{"name":"devise_invitable","ecosystem":"RubyGems","purl":"pkg:gem/devise_invitable"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.5"}]}],"versions":["0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.2.0","0.2.1","0.2.2","0.2.3","0.3.0","0.3.1","0.3.2","0.3.4","0.3.5","0.3.6","0.3.7","0.4.0","0.4.1","0.4.2","0.4.rc","0.4.rc2","0.4.rc3","0.4.rc4","0.4.rc5","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.5.5","0.5.6","0.5.7","0.6.0","0.6.1","1.0.0","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.2.1","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-wj5j-xpcj-45gc/GHSA-wj5j-xpcj-45gc.json"}}],"schema_version":"1.9.0"}