CVE-2021-22885
7.5HIGHA possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Veröffentlicht: 5/27/2021Aktualisiert: 11/21/2024
Beschreibung
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
KI-AnalyseKI-gestützt
Betroffene Produkte
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsactionpack_page-caching
-
debiandebian_linux
10.0
Referenzen
- https://hackerone.com/reports/1106652ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0009/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4929Third Party Advisory
- https://hackerone.com/reports/1106652ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0009/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4929Third Party Advisory