The PgHero gem through 2.6.0 for Ruby allows CSRF.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-16253.json"