Description
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin The Events Calendar Security Bypass (3.11.2)
WordPress Plugin Ad-Manager Open Redirect (1.1.2)
WordPress Plugin Sync to Etsy Marketplace from WooCommerce Cross-Site Request Forgery (3.3.1)
MySQL CVE-2015-0507 Vulnerability (CVE-2015-0507)
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16186)