A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the redirect_to or polymorphic_urlhelper with untrusted user input.
{
"versions": [
{
"introduced": "5.2.0.0"
},
{
"fixed": "5.2.4.6"
},
{
"introduced": "6.0.0.0"
},
{
"fixed": "6.0.3.7"
},
{
"introduced": "6.1.0.0"
},
{
"fixed": "6.1.3.1"
}
]
}