CVE-2021-22942
MEDIUM6.1EPSS 0.53%rails - security update
發布日:2021/8/26修改日:2026/4/28
描述
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.
受影響套件(3)
- Debian/railsfrom 0, < 2:6.0.3.7+dfsg-2+deb11u1
- Debian/railsfrom 0, < 2:6.0.3.7+dfsg-2+deb11u1
- RubyGems/actionpack>= 6.0.0, < 6.0.4.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
參考連結(11)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2021-22942
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2021-22942
- PATCHhttps://github.com/rails/rails
- WEBhttps://access.redhat.com/security/cve/cve-2021-22942
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2021-22942.yml
- WEBhttps://groups.google.com/g/rubyonrails-security/c/wB5tRn7h36c
- WEBhttps://rubygems.org/gems/actionpack
- WEBhttps://security.netapp.com/advisory/ntap-20240202-0005
- WEBhttps://weblog.rubyonrails.org/2021/8/19/Rails-6-0-4-1-and-6-1-4-1-have-been-released
- WEBhttps://www.debian.org/security/2023/dsa-5372
- WEBhttp://www.openwall.com/lists/oss-security/2021/12/14/5