Description
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Remediation
References
Related Vulnerabilities
Jboss EAP Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2011-2487)
Oracle Database Server CVE-2019-2913 Vulnerability (CVE-2019-2913)
WordPress Plugin MailChimp for WooCommerce Local File Inclusion (2.1.1)
WordPress Plugin SE HTML5 Album Audio Player Directory Traversal (1.1.0)