CVE-2008-5189
Ruby on Rails <2.0.5 - RCE
Title source: llmDescription
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.
References (5)
Scores
EPSS
0.0017
EPSS Percentile
38.0%
Classification
CWE
CWE-352
Status
draft
Affected Products (50)
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
rubyonrails/rails
... and 35 more
Timeline
Published
Nov 21, 2008
Tracked Since
Feb 18, 2026