The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade foreman-cliUpgrade satellite-cli | Dec 19, 2023 | Dec 19, 2023 |
| Debian | — | Upgrade rails | Mar 19, 2025 | Jan 9, 2025 |
| Suse | — | Upgrade ruby2.5-rubygem-actionpack-doc-5_1Upgrade ruby2.5-rubygem-actionpack-5_1 | Aug 9, 2023 | Aug 8, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub