Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hpq-rjcx-7vj9

Опубликовано: 13 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.6

Описание

Clearance Gem Open Redirect Vulnerability

This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).

Пакеты

Наименование

clearance

rubygems
Затронутые версииВерсия исправления

< 2.5.0

2.5.0

EPSS

Процентиль: 51%
0.00282
Низкий

7.6 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 7.6
nvd
больше 4 лет назад

This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).

EPSS

Процентиль: 51%
0.00282
Низкий

7.6 High

CVSS3

Дефекты

CWE-601