CVE-2008-5189

Ruby on Rails < 2.0.5 - CRLF Injection via redirect_to Function

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.

Scores

EPSS 0.0017
EPSS Percentile 37.7%

Details

CWE
CWE-352
Status published
Products (48)
rubygems/rails 0 - 2.0.5RubyGems
rubyonrails/rails 0.9.1
rubyonrails/rails 0.9.2
rubyonrails/rails 0.9.3
rubyonrails/rails 0.9.4
rubyonrails/rails 0.9.4.1
rubyonrails/rails 0.10.0
rubyonrails/rails 0.10.1
rubyonrails/rails 0.11.0
rubyonrails/rails 0.11.1
... and 38 more
Published Nov 21, 2008
Tracked Since Feb 18, 2026