A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.
2021-10-18T13:15:09.323
2024-11-21T05:50:59.093
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rubyonrails | rails | < 6.0.4.1 | Yes |
Application | rubyonrails | rails | < 6.1.4.1 | Yes |