CVE-2023-28362

MEDIUM

Rails - Open Redirect

Title source: llm
STIX 2.1

Description

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.

Scores

CVSS v3 4.0
EPSS 0.0021
EPSS Percentile 42.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (3)
Rails/Action Pack 6.1.7.4
Rails/Action Pack 7.0.5.1
rubygems/actionpack 0 - 6.1.7.4RubyGems
Published Jan 09, 2025
Tracked Since Feb 18, 2026