PT-2025-34903 · Rails +1 · Rails +1
Muntrive
·
Published
2025-08-27
·
Updated
2025-08-28
·
CVE-2025-57821
4.2
Medium
Base vector | Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Basecamp Google Sign-In versions prior to 1.3.0
Description:
A malformed URL can bypass the "same origin" check, potentially redirecting users to an unintended origin. This issue affects Rails applications using the library and storing flash information in a session cookie, which could be chained with an attack that allows arbitrary data injection into the session cookie.
Recommendations:
Basecamp Google Sign-In versions prior to 1.3.0: Upgrade to version 1.3.0 or later.
Basecamp Google Sign-In versions prior to 1.3.0: If upgrading is not possible, explicitly set `SameSite=Lax` or `SameSite=Strict` on the application session cookie to mitigate the chained attack.
Exploit
Fix
Open Redirect
Weakness Enumeration
Related Identifiers
Affected Products
References · 15
- 🔥 https://github.com/rubysec/ruby-advisory-db/blob/master/gems/google_sign_in/CVE-2025-57821.yml⭐ 1033 🔗 221 · Exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-57821 · Security Note
- https://osv.dev/vulnerability/GHSA-7pwc-wh6m-44q3 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2025-57821 · Vendor Advisory
- https://github.com/basecamp/google_sign_in/releases/tag/v1.3.0⭐ 543 🔗 55 · Note
- https://github.com/basecamp/google_sign_in/commit/85903651201257d4f14b97d4582e6d968ac32f15⭐ 543 🔗 55 · Note
- https://github.com/basecamp/google_sign_in/pull/73⭐ 543 🔗 55 · Note
- https://github.com/basecamp/google_sign_in/security/advisories/GHSA-7pwc-wh6m-44q3⭐ 543 🔗 55 · Note
- https://github.com/basecamp/google_sign_in/commit/a0548a604fb17e4eb1a57029f0d87e34e8499623⭐ 542 🔗 55 · Note
- https://github.com/basecamp/google_sign_in⭐ 542 🔗 55 · Note
- https://t.me/CVEtracker/31039 · Telegram Post
- https://twitter.com/rubylandnews/status/1961192137359237558 · Twitter Post
- https://twitter.com/CVEnew/status/1960745842375319977 · Twitter Post
- https://twitter.com/Muntrive/status/1960804870006694105 · Twitter Post
- https://twitter.com/VulmonFeeds/status/1960842252646793229 · Twitter Post