jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value.
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | PoC | E: U→P | 0.0 → 0.0 |
| 2026-07-21 | cve.org | initial, patch: Unavailable | 0.0 |
Affected Software
| Vendor | Product | Version |
|---|
| fedoraproject | fedora | 21 |
| fedoraproject | fedora | 22 |
| opensuse | opensuse | 13.1 |
| opensuse | opensuse | 13.2 |
| rubyonrails | jquery-rails | ≤ 3.1.2 |
| rubyonrails | jquery-rails | 4.0.0 |
| rubyonrails | jquery-rails | 4.0.1 |
| rubyonrails | jquery-ujs | ≤ 1.0.3 |
Published: 2015-07-26