• CVE-2023-22797

发布时间: 2023年3月1日

修改时间: 2023年3月1日

概要

An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability.

CVSS v3 指标

NVD openEuler
CVSS评分 6.1 6.5
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required None None
User Interaction Required None
Scope Changed Unchanged
Confidentiality Low Low
Integrity Low Low
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2023-1128 An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability. 2023年3月1日

影响产品

产品 状态
KY3.4-4A rubygem-actionpack Unaffected
KY3.4-5 rubygem-actionpack Unaffected
KY3.5.1 rubygem-actionpack Unaffected
KY3.5.2 rubygem-actionpack Unaffected