A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
{ "binaries": [ { "binary_name": "rails", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-actioncable", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-actionmailbox", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-actionmailer", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-actionpack", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-actiontext", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-actionview", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-activejob", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-activemodel", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-activerecord", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-activestorage", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-activesupport", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-rails", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" }, { "binary_name": "ruby-railties", "binary_version": "2:6.1.4.1+dfsg-8ubuntu2" } ] }
{ "binaries": [ { "binary_name": "rails", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-actioncable", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-actionmailbox", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-actionmailer", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-actionpack", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-actiontext", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-actionview", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-activejob", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-activemodel", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-activerecord", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-activestorage", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-activesupport", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-rails", "binary_version": "2:6.1.7.3+dfsg-3" }, { "binary_name": "ruby-railties", "binary_version": "2:6.1.7.3+dfsg-3" } ] }
{ "binaries": [ { "binary_name": "rails", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-actioncable", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-actionmailbox", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-actionmailer", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-actionpack", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-actiontext", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-actionview", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-activejob", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-activemodel", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-activerecord", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-activestorage", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-activesupport", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-rails", "binary_version": "2:6.1.7.3+dfsg-7" }, { "binary_name": "ruby-railties", "binary_version": "2:6.1.7.3+dfsg-7" } ] }