Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2023-28362

больше 1 года назад

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2023-28362

около 3 лет назад

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2023-28362

больше 1 года назад

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2023-28362

больше 1 года назад

The redirect_to method in Rails allows provided values to contain char ...

CVSS3: 4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3229-1

около 3 лет назад

Security update for rubygem-actionpack-5_1

EPSS: Низкий
github логотип

GHSA-4g8v-vg43-wpgf

около 3 лет назад

Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to

CVSS3: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-28362

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.

CVSS3: 4
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-28362

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.

CVSS3: 4.7
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-28362

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.

CVSS3: 4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-28362

The redirect_to method in Rails allows provided values to contain char ...

CVSS3: 4
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3229-1

Security update for rubygem-actionpack-5_1

0%
Низкий
около 3 лет назад
github логотип
GHSA-4g8v-vg43-wpgf

Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to

CVSS3: 4
0%
Низкий
около 3 лет назад

Уязвимостей на страницу