VDB

CISA-2023-22797

CISA-2023-22797 PUBLISHED CVSS 6.1 MEDIUM

Reported by hackerone · Published February 9, 2023

An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability.

Risk Scores

CVSS 3.1
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
n/ahttps://github.com/rails/rails7.0.4.1
n/ahttps://github.com/rails/rails7.0.4.1, 7.0.4.1

Timeline

  • Feb 9, 2023 CVE Published
  • Mar 24, 2025 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›