CVE-2023-22797
09.02.2023, 20:15
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability.
Vendor | Product | Version |
---|---|---|
actionpack_project | actionpack | 7.0.0 ≤ 𝑥 < 7.0.4.1 |
rubyonrails | rails | 7.0.0 ≤ 𝑥 < 7.0.4.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
rails |
| ||||||||||||||||||||
rails-4.0 |
| ||||||||||||||||||||
ruby-actionpack-3.2 |
| ||||||||||||||||||||
ruby-activemodel-3.2 |
| ||||||||||||||||||||
ruby-activerecord-3.2 |
| ||||||||||||||||||||
ruby-activesupport-3.2 |
| ||||||||||||||||||||
ruby-rails-3.2 |
|
Common Weakness Enumeration