Bug 1182160 - (CVE-2021-22881) VUL-0: CVE-2021-22881: rubygem-actionpack: open redirect vulnerability via `Host` headers
(CVE-2021-22881)
VUL-0: CVE-2021-22881: rubygem-actionpack: open redirect vulnerability via `H...
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P5 - None : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/277825/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-02-12 08:34 UTC by Alexander Bergmann
Modified: 2021-02-12 08:37 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2021-02-12 08:34:20 UTC
CVE-2021-22881

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers
from an open redirect vulnerability. Specially crafted `Host` headers in
combination with certain "allowed host" formats can cause the Host Authorization
middleware in Action Pack to redirect users to a malicious website. Impacted
applications will have allowed hosts with a leading dot. When an allowed host
contains a leading dot, a specially crafted `Host` header can be used to
redirect to a malicious website.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-22881
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22881
https://discuss.rubyonrails.org/t/cve-2021-22881-possible-open-redirect-in-host-authorization-middleware/77130
https://hackerone.com/reports/1047447
Comment 1 Alexander Bergmann 2021-02-12 08:37:44 UTC
https://discuss.rubyonrails.org/t/cve-2021-22881-possible-open-redirect-in-host-authorization-middleware/77130

Not affected: < 6.0.0
Fixed Versions: 6.1.2.1, 6.0.3.5

Only Factory is affected. All SUSE and openSUSE versions are prior 6.0.0.

openSUSE:Factory/rubygem-actionpack-6.0


Closing bug.