V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-22881
DEB
Medium

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Ho…

CVSS
6.1
Medium
EPSS
0.87
p99
Published
2021-01-01
Updated
2021-01-01
Description

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted applications will have allowed hosts with a leading dot. When an allowed host contains a leading dot, a specially crafted `Host` header can be used to redirect to a malicious website.

Tags · CWE
Pre-authOpen redirect
CWE-601
CAPEC-178
Affected products
Gem-actioncableGem-actioncable-develGem-actioncable-docGem-actionmailboxGem-actionmailbox-develGem-actionmailbox-docGem-actionmailerGem-actionmailer-develGem-actionmailer-docGem-actionpackGem-actionpack-develGem-actionpack-docGem-actiontextGem-actiontext-develGem-actiontext-docGem-actionviewGem-actionview-develGem-actionview-docGem-activejobGem-activejob-devel
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.873 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
gem-actioncableTracked
gem-actioncable-develTracked
gem-actioncable-docTracked
gem-actionmailboxTracked
gem-actionmailbox-develTracked
gem-actionmailbox-docTracked
gem-actionmailerTracked
gem-actionmailer-develTracked
gem-actionmailer-docTracked
gem-actionpackTracked
gem-actionpack-develTracked
gem-actionpack-docTracked
gem-actiontextTracked
gem-actiontext-develTracked
gem-actiontext-docTracked
gem-actionviewTracked
gem-actionview-develTracked
gem-actionview-docTracked
gem-activejobTracked
gem-activejob-develTracked
Showing first 20 of 62
Source databases
DEB
CVE
RED
UBU