描述
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
AI分析AI驱动
受影响产品
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsactionpack_page-caching
-
debiandebian_linux
10.0
参考资料
- https://hackerone.com/reports/1106652ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0009/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4929Third Party Advisory
- https://hackerone.com/reports/1106652ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0009/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4929Third Party Advisory