VDB
Sign up
MEDIUM6.1

GHSA-8877-prq4-9xfw

Actionpack Open Redirect Vulnerability

Quick fix

GHSA-8877-prq4-9xfw — actionpack: upgrade to the fixed version with the command below.

bundle update actionpack

Details

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/actionpack
Introduced in: 6.0.0Fixed in: 6.0.3.5
Fixbundle update actionpack
RubyGems/actionpack
Introduced in: 6.1.0Fixed in: 6.1.2.1
Fixbundle update actionpack

References