Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29385
HistoryFeb 15, 2021 - 3:48 a.m.

Open Redirection

2021-02-1503:48:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
27
rails
open redirection
validation bypass
malicious host header
redirect vulnerability
regex matching

EPSS

0.002

Percentile

61.0%

rails is vulnerable to open redirection. Inadequate validation and regex matching of URLs allows an attacker to bypass validation checks using a malicious Host header and redirect users to a malicious website.