CVE-2023-22797
09.02.2023, 20:15
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability.
| Vendor | Product | Version |
|---|---|---|
| actionpack_project | actionpack | 7.0.0 ≤ 𝑥 < 7.0.4.1 |
| rubyonrails | rails | 7.0.0 ≤ 𝑥 < 7.0.4.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rails |
| ||||||||||||||||||||
| rails-4.0 |
| ||||||||||||||||||||
| ruby-actionpack-3.2 |
| ||||||||||||||||||||
| ruby-activemodel-3.2 |
| ||||||||||||||||||||
| ruby-activerecord-3.2 |
| ||||||||||||||||||||
| ruby-activesupport-3.2 |
| ||||||||||||||||||||
| ruby-rails-3.2 |
|
Common Weakness Enumeration