VDB
KO
MEDIUM 6.1

GHSA-8877-prq4-9xfw

Actionpack Open Redirect Vulnerability

Details

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / actionpack
Introduced in: 6.0.0 Fixed in: 6.0.3.5
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 6.1.0 Fixed in: 6.1.2.1
Fix bundle update actionpack

References