OESA-2021-1236
Dashboard / Vulnerabilities / OESA-2021-1236
Summary: rubygem-actionpack security update
Details: Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn't require a browser. Security Fix(es): A possible information disclosure/unintended method execution vulnerability in Action Pack >= 2.0.0 when using the redirect_to or polymorphic_urlhelper with untrusted user input.(CVE-2021-22885)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1236, https://nvd.nist.gov/vuln/detail/CVE-2021-22885
Affected packages
Package
Name: rubygem-actionpack
Purl: pkg:rpm/openEuler/rubygem-actionpack&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
