Description
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Remediation
References
Related Vulnerabilities
Jenkins Missing Authorization Vulnerability (CVE-2021-21694)
WordPress Plugin WP DSGVO Tools (GDPR) Unspecified Vulnerability (3.1.26)
WordPress Plugin Asgaros Forum Cross-Site Request Forgery (1.5.8)
WordPress Plugin ALO EasyMail Newsletter Multiple Cross-Site Scripting Vulnerabilities (2.4.7)
Oracle Database Server CVE-2013-3789 Vulnerability (CVE-2013-3789)