{"id":"CVE-2020-16253","aliases":["GHSA-v6fx-752r-ccp2"],"url":"https://o3.security/vulnerability/CVE-2020-16253","summary":"PgHero gem allows CSRF","details":"The PgHero gem through 2.6.0 for Ruby allows CSRF. PgHero normally uses the `protect_from_forgery` method from Rails to prevent CSRF. However, this defaults to `:null_session`, which has no effect on non-session based authentication methods. Thus the ruby gem is vulnerable with non-session based authentication methods like basic authentication.","published":"2020-08-05T14:15:12.750Z","modified":"2026-07-08T19:03:26.178448Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"pghero","fixedVersion":"2.7.0"}],"fix":{"url":"https://github.com/ankane/pghero/commit/14b67b32fed19a30aaf9826ee72f2a29cda604e9","label":"ankane/pghero@14b67b3"},"references":[{"type":"ADVISORY","url":"https://github.com/ankane/pghero/"},{"type":"ADVISORY","url":"https://github.com/ankane/pghero/issues/330"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-16253"},{"type":"WEB","url":"https://github.com/ankane/pghero/commit/14b67b32fed19a30aaf9826ee72f2a29cda604e9"},{"type":"PACKAGE","url":"https://github.com/ankane/pghero"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/pghero/CVE-2020-16253.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:03:26.178448Z"}}