RubySec

Providing security resources for the Ruby community

CVE-2008-5189 (rails): Moderate severity vulnerability that affects rails

ADVISORIES

GEM

rails

FRAMEWORK

Ruby on Rails

SEVERITY

CVSS v2.0: 5.0 (Medium)

PATCHED VERSIONS

  • >= 2.0.5

DESCRIPTION

CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.

RELATED