{"id":"CVE-2021-23435","aliases":["GHSA-4hpq-rjcx-7vj9","SNYK-RUBY-CLEARANCE-1577284"],"url":"https://o3.security/vulnerability/CVE-2021-23435","summary":"Clearance Gem Open Redirect Vulnerability","details":"This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).","published":"2021-09-12T20:15:07.443Z","modified":"2026-07-09T14:43:46.684821Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"clearance","fixedVersion":"2.5.0"}],"fix":{"url":"https://github.com/thoughtbot/clearance/pull/945","label":"thoughtbot/clearance#945"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-RUBY-CLEARANCE-1577284"},{"type":"FIX","url":"https://github.com/thoughtbot/clearance/pull/945"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T14:43:46.684821Z"}}