CVE Database
/

CVE-2023-28362

Back to search

CVE-2023-28362

Published: Jan 9, 2025

Modified: May 2, 2025

PUBLISHED

Description

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header.

VendorProductVersions

Rails

Action Pack

affected
7.0.5.1 - < 7.0.5.1
affected
6.1.7.4 - < 6.1.7.4

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now