Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22885

Опубликовано: 05 мая 2021
Источник: redhat
CVSS3: 7.5

Описание

A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the redirect_to or polymorphic_urlhelper with untrusted user input.

A flaw was found in rubygem-actionpack. Information disclosure or unintended method execution is possible when using the redirect_to or polymorphic_url helper with untrusted user input. The highest threat from this vulnerability is to data confidentiality.

Отчет

Red Hat CloudForms is in the maintenance phase and we will not be fixing Medium/Low impact security bugs. Reference: https://access.redhat.com/support/policy/updates/cloudforms

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-gemsetWill not fix
Red Hat 3scale API Management Platform 2systemAffected
Red Hat Satellite 6tfm-ror52-rubygem-actionpackWill not fix
Red Hat Satellite 6.10 for RHEL 7tfm-rubygem-actionpackFixedRHSA-2021:470216.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1957441rubygem-actionpack: Possible Information Disclosure / Unintended Method Execution in Action Pack

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.

CVSS3: 7.5
nvd
больше 4 лет назад

A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.

CVSS3: 7.5
debian
больше 4 лет назад

A possible information disclosure / unintended method execution vulner ...

suse-cvrf
больше 4 лет назад

Security update for rubygem-actionpack-5_1

suse-cvrf
больше 4 лет назад

Security update for rubygem-actionpack-5_1

7.5 High

CVSS3