Количество 6
Количество 6
CVE-2023-28362
The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.
CVE-2023-28362
The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.
CVE-2023-28362
The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.
CVE-2023-28362
The redirect_to method in Rails allows provided values to contain char ...
SUSE-SU-2023:3229-1
Security update for rubygem-actionpack-5_1
GHSA-4g8v-vg43-wpgf
Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-28362 The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. | CVSS3: 4 | 0% Низкий | больше 1 года назад | |
CVE-2023-28362 The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. | CVSS3: 4.7 | 0% Низкий | около 3 лет назад | |
CVE-2023-28362 The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. | CVSS3: 4 | 0% Низкий | больше 1 года назад | |
CVE-2023-28362 The redirect_to method in Rails allows provided values to contain char ... | CVSS3: 4 | 0% Низкий | больше 1 года назад | |
SUSE-SU-2023:3229-1 Security update for rubygem-actionpack-5_1 | 0% Низкий | около 3 лет назад | ||
GHSA-4g8v-vg43-wpgf Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to | CVSS3: 4 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу