Open Redirect Vulnerability in Rails 7.0.4.1 by Ruby on Rails
CVE-2023-22797

6.1MEDIUM

Key Information:

Vendor
CVE Published:
9 February 2023

What is CVE-2023-22797?

An open redirect vulnerability was addressed in Rails 7.0.4.1, which implemented enhanced protection against untrusted user input when using the redirect_to method. Earlier versions placed the onus on developers to ensure that the input was safe, potentially allowing attackers to exploit the system with strategically crafted URLs and redirect users to untrusted sites. The new mechanism aims to mitigate this risk by enforcing stricter validation checks.

Affected Version(s)

https://github.com/rails/rails 7.0.4.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.