{"id":"GHSA-p4xx-w6fr-c4w9","summary":"Clockwork Web contains a Cross-Site Request Forgery Vulnerability with Rails \u003c 5.2","details":"Clockwork Web before 0.1.2, when used with Rails before 5.2 is used, allows Cross-Site Request Forgery (CSRF). A CSRF attack works by getting an authorized user to visit a malicious website and then performing requests on behalf of the user. In this instance, actions include enabling and disabling jobs. All users running an affected release on Rails \u003c 5.2 should upgrade immediately.","aliases":["CVE-2023-25015"],"modified":"2025-03-26T20:17:48.197878Z","published":"2023-02-02T06:30:26Z","database_specific":{"github_reviewed_at":"2023-02-02T23:07:04Z","nvd_published_at":"2023-02-02T04:15:00Z","cwe_ids":["CWE-352","CWE-652"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25015"},{"type":"WEB","url":"https://github.com/ankane/clockwork_web/issues/4"},{"type":"WEB","url":"https://github.com/ankane/clockwork_web/commit/ec2896503ee231588547c2fad4cb93a94e78f857"},{"type":"PACKAGE","url":"https://github.com/ankane/clockwork_web"},{"type":"WEB","url":"https://github.com/ankane/clockwork_web/compare/v0.1.1...v0.1.2"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/clockwork_web/CVE-2023-25015.yml"}],"affected":[{"package":{"name":"clockwork_web","ecosystem":"RubyGems","purl":"pkg:gem/clockwork_web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.2"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.1.0","0.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-p4xx-w6fr-c4w9/GHSA-p4xx-w6fr-c4w9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}