Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22942

Опубликовано: 20 авг. 2021
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

A flaw was found in rubygem-actionpack. Specially crafted “X-Forwarded-Host” headers, in combination with certain “allowed host” formats, can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. The highest threat from this vulnerability is to system availability.

Отчет

Red Hat Satellite 6 does ship affected version of RubyGem Actionpack, however, product is not vulnerable as it does not set host configuration the vulnerable way.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-gemsetNot affected
Red Hat Satellite 6rubygem-actionpackWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1995940rubygem-actionpack: possible open redirect in the Host Authorization middleware

EPSS

Процентиль: 69%
0.0061
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 4 лет назад

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

CVSS3: 6.1
nvd
больше 4 лет назад

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

CVSS3: 6.1
debian
больше 4 лет назад

A possible open redirect vulnerability in the Host Authorization middl ...

CVSS3: 6.1
github
больше 4 лет назад

Open Redirect in ActionPack

EPSS

Процентиль: 69%
0.0061
Низкий

5.4 Medium

CVSS3