CVE-2023-28362

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Jan 9, 2025
CWE ID 116

Summary

CVE-2023-28362 is a vulnerability affecting the redirect_to method in Rails. This issue allows for input containing characters that are not valid in HTTP header values. Consequently, downstream services that enforce RFC compliance on HTTP response headers may strip the assigned Location header, potentially leading to redirection failures or unintended redirects. This could result in security vulnerabilities, such as unauthorized access or data leakage, if an attacker is able to manipulate the HTTP response headers. Developers are advised to update their Rails applications to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share