UBUNTU-CVE-2021-22903
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-22903
Summary:
Details: The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, `config.hosts << "sub.example.com"` to permit a request with a Host header value of `sub-example.com`.
References: https://ubuntu.com/security/CVE-2021-22903, https://www.cve.org/CVERecord?id=CVE-2021-22903
Affected packages
Package
Name: rails
Purl: pkg:deb/ubuntu/rails?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
