better_errors
Provides a better error page for Rails and other Rack apps. Includes source code inspection, a live REPL and local/instance variable inspection for all stack frames.
Activity
- Latest release
- 3y ago
- Total releases
- 44
- Cadence
- ~10 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Dec 08, 2012
| Version | Released | |
|---|---|---|
2.10.1
patch
|
2.10.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.10.0
minor
|
2.10.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.10.0.beta2
pre
|
2.10.0.beta2
pre
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.10.0.beta1
pre
|
2.10.0.beta1
pre
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.9.1
patch
|
2.9.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.9.0
minor
|
2.9.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.8.3
patch
|
2.8.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.8.2
patch
|
2.8.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.8.1
patch
|
2.8.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.8.0
minor
|
2.8.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.7.1
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.7.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.7.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.7.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.6.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.5.1
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.0.rc1
pre
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.9.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.8.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.7.2
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.7.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.6.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.1.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.8
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.4
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.7
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.3
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.6
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.5
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.2
patch
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.0.1
initial
1 CVE
CVE-2021-39197
GHSA-w3j4-76qw-wwjm
Sep 07, 2021
Older releases of better_errors open to Cross-Site Request Forgery attack
6.3
/ 10
Medium
Network
High
Low
None
Changed
High
None
None
Impactbetter_errors prior to 2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct "Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without CORS protection. These together left an application with better_errors enabled open to cross-origin attacks. As a developer tool, better_errors documentation strongly recommends addition only to the PatchesStarting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest release, or minimally to "~> 2.8.3". WorkaroundsThere are no known workarounds to mitigate the risk of using older releases of better_errors. References
For more informationIf you have any questions or comments about this advisory, please
Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.1.0
0.1.1
0.2.0
0.3.0
+ 22 more Show less
0.3.2
0.5.0
0.6.0
0.7.0
0.7.2
0.8.0
0.9.0
1.0.0
1.0.0.rc1
1.0.1
1.1.0
2.0.0
2.1.0
2.1.1
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.7.1
Fixed in
2.8.0
References
Updated Jul 08, 2026 · Source: OSV.dev |