Skip to content

Add advisory for will_paginate #272

Description

@aripollak

Apparently there was a security issue fixed here: mislav/will_paginate@ec9b985 and here: mislav/will_paginate@ab55687

It looks like versions before 3.1.2, 3.0.9, and are vulnerable, but this has no CVE and I'm not sure exactly what the vulnerability was.

Activity

  1. aripollak commented on Oct 28, 2016

    @aripollak
    Author

    With a bit of experimentation, I discovered that adding &script_name=https://www.example.com to a page with will_paginate links would result in the links being rewritten to be https://www.example.com... instead of the intended site. I guess someone could use this in a social engineering attack by sending someone a link with &script_name being a malicious site and hoping they click on the pagination links and getting fooled, but I'm not sure if it's any worse than that.

  2. jasnow commented on Jun 3, 2023

    @jasnow
    Member

    @aripollak or @phillmv - Is this issue related to this existing advisory - gems/will_paginate/CVE-2013-6459.yml ?
    Thanks

  3. aripollak commented on Jun 3, 2023

    @aripollak
    Author

    @jasnow I think that's a different issue.

  4. jasnow commented on Jul 23, 2026

    @jasnow
    Member

    Here is what I know about this issue (in advisory/yaml format) with notes:

    Since this repo does not create contents or CVEs/GHSAs, I will be closing
    this issue shortly. Speak up if you want to work on this.

  5. jasnow commented on Jul 24, 2026

    @jasnow
    Member

    Acting on my previous comment, I am closing this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions