GHSA-4hpq-rjcx-7vj9

Suggest an improvement
Source
https://github.com/advisories/GHSA-4hpq-rjcx-7vj9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-4hpq-rjcx-7vj9/GHSA-4hpq-rjcx-7vj9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4hpq-rjcx-7vj9
Aliases
Published
2021-09-13T20:05:09Z
Modified
2026-07-08T06:49:52Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H CVSS Calculator
Summary
Clearance Gem Open Redirect Vulnerability
Details

This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).

Database specific
{
    "cwe_ids":  [
        "CWE-601"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-09-13T19:07:07Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

RubyGems / clearance

Package

Name
clearance
Purl
pkg:gem/clearance

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.5.0

Affected versions

0.*
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0.rc1
0.9.0.rc2
0.9.0.rc3
0.9.0.rc4
0.9.0.rc5
0.9.0.rc6
0.9.0.rc7
0.9.0.rc8
0.9.0.rc9
0.9.1
0.10.0
0.10.1
0.10.2
0.10.3.2
0.10.4
0.10.5
0.11.0
0.11.1
0.11.2
0.12.0
0.13.0
0.13.2
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
1.*
1.0.0.rc1
1.0.0.rc2
1.0.0.rc3
1.0.0.rc4
1.0.0.rc6
1.0.0.rc7
1.0.0.rc8
1.0.0
1.0.1
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
1.8.0
1.8.1
1.9.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.16.0
1.16.1
1.16.2
1.17.0
2.*
2.0.0.beta1
2.0.0.beta2
2.0.0
2.1.0
2.2.0
2.2.1
2.3.0
2.3.1
2.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-4hpq-rjcx-7vj9/GHSA-4hpq-rjcx-7vj9.json"