Lucene search

K
osvGoogleOSV:CVE-2021-23435
HistorySep 12, 2021 - 8:15 p.m.

CVE-2021-23435

2021-09-1220:15:07
Google
osv.dev
7

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.3%

This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.3%