CVE-2008-5189

Ruby on Rails <2.0.5 - RCE

Title source: llm

Description

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.

Scores

EPSS 0.0017
EPSS Percentile 38.0%

Classification

CWE
CWE-352
Status draft

Affected Products (50)

rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
... and 35 more

Timeline

Published Nov 21, 2008
Tracked Since Feb 18, 2026