Description
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a carefully crafted URL resulting in an open redirect vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Broken Link Checker Cross-Site Scripting (1.10.5)
PHP Resource Management Errors Vulnerability (CVE-2006-1549)
WordPress Plugin Gutenberg Blocks by WordPress Download Manager Cross-Site Scripting (2.1.8)
WordPress 5.1.x Cross-Site Request Forgery (5.1)
WordPress Plugin WP Business Directory Cross-Site Scripting (1.0.5)