Количество 2
Количество 2
CVE-2021-23435
This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).
GHSA-4hpq-rjcx-7vj9
Clearance Gem Open Redirect Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-23435 This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com). | CVSS3: 7.6 | 0% Низкий | больше 4 лет назад | |
GHSA-4hpq-rjcx-7vj9 Clearance Gem Open Redirect Vulnerability | CVSS3: 7.6 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу