Recurly gem Server-Side Request Forgery in Resource#find method
Critical severity
GitHub Reviewed
Published
Dec 6, 2017
to the GitHub Advisory Database
•
Updated Aug 29, 2023
Package
Affected versions
>= 2.11.0, < 2.11.3
>= 2.10.0, < 2.10.4
>= 2.9.0, < 2.9.2
>= 2.8.0, < 2.8.2
>= 2.7.0, < 2.7.8
>= 2.6.0, < 2.6.3
>= 2.5.0, < 2.5.4
>= 2.4.0, < 2.4.11
>= 2.3.0, < 2.3.10
>= 2.2.0, < 2.2.5
>= 2.1.0, < 2.1.11
>= 2.0.0, < 2.0.13
Patched versions
2.11.3
2.10.4
2.9.2
2.8.2
2.7.8
2.6.3
2.5.4
2.4.11
2.3.10
2.2.5
2.1.11
2.0.13
Description
Published to the GitHub Advisory Database
Dec 6, 2017
Reviewed
Jun 16, 2020
Last updated
Aug 29, 2023
The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the
Resource#find
method that could result in compromise of API keys or other critical resources.References