QID 376258
Date Published: 2022-01-20
QID 376258: Ruby Gem Clearance Open Redirect Vulnerability
Affected versions of clearance are vulnerable to Open Redirect. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).
Affected Versions:
Clearance versions prior to version 2.5.0 are vulnerable.
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of Clearance installed
Successful exploitation of the vulnerability may allow an attacker to redirect a user to a malicious website of attacker's choosing.
Solution
Customers are advised to upgrade to Clearance version 2.5.0 or later. For more information, please refer to Clearance Release Notes
Vendor References
- Clearance Release Notes -
github.com/thoughtbot/clearance/releases/tag/v2.5.0
CVEs related to QID 376258
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|