The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Ho…
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted applications will have allowed hosts with a leading dot. When an allowed host contains a leading dot, a specially crafted `Host` header can be used to redirect to a malicious website.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
https://cwe.mitre.org/data/definitions/601.html →Open in CWE collection →An attacker is able to trick the victim into executing a Flash document that passes commands or calls to a Flash player browser plugin, allowing the attacker to exploit native Flash functionality in the client browser. This attack pattern occurs where an attacker can provide a crafted link to a Flash document (SWF file) which, when followed, will cause additional malicious instructions to be executed. The attacker does not need to serve or control the Flash document. The attack takes advantage of the fact that Flash files can reference external URLs. If variables that serve as URLs that the Flash application references can be controlled through parameters, then by creating a link that includes values for those parameters, an attacker can cause arbitrary content to be referenced and possibly executed by the targeted Flash application.
https://capec.mitre.org/data/definitions/178.html →Open in CAPEC collection →| Product | Vendor | Status |
|---|---|---|
| gem-actioncable | Tracked | |
| gem-actioncable-devel | Tracked | |
| gem-actioncable-doc | Tracked | |
| gem-actionmailbox | Tracked | |
| gem-actionmailbox-devel | Tracked | |
| gem-actionmailbox-doc | Tracked | |
| gem-actionmailer | Tracked | |
| gem-actionmailer-devel | Tracked | |
| gem-actionmailer-doc | Tracked | |
| gem-actionpack | Tracked | |
| gem-actionpack-devel | Tracked | |
| gem-actionpack-doc | Tracked | |
| gem-actiontext | Tracked | |
| gem-actiontext-devel | Tracked | |
| gem-actiontext-doc | Tracked | |
| gem-actionview | Tracked | |
| gem-actionview-devel | Tracked | |
| gem-actionview-doc | Tracked | |
| gem-activejob | Tracked | |
| gem-activejob-devel | Tracked |