GHSA-4g8v-vg43-wpgf

    Dashboard / Vulnerabilities / GHSA-4g8v-vg43-wpgf

    GHSA-4g8v-vg43-wpgf

    Published: 29 Jun 2023Last Modified: 5 May 2025

    Summary: Actionpack has possible cross-site scripting vulnerability via User Supplied Values to redirect_to

    Details: The `redirect_to` method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned Location header. This vulnerability has been assigned the CVE identifier CVE-2023-28362. Versions Affected: All. Not affected: None Fixed Versions: 7.0.5.1, 6.1.7.4 # Impact This introduces the potential for a Cross-site-scripting (XSS) payload to be delivered on the now static redirection page. Note that this both requires user interaction and for a Rails app to be configured to allow redirects to external hosts (defaults to false in Rails >= 7.0.x). # Releases The FIXED releases are available at the normal locations. # Workarounds Avoid providing user supplied URLs with arbitrary schemes to the `redirect_to` method.

    Affected packages

    Package

    Name: actionpack

    Purl: pkg:gem/actionpack

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -6.1.7.4

    Affected versions

    0.9.0
    0.9.5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4g8v-vg43-wpgf | CVE-DB