CVE-2021-22885
7.5HIGHA possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Publicado: 5/27/2021Actualizado: 11/21/2024
Descripción
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
Análisis IAImpulsado por IA
Productos Afectados
rubyonrailsrails
rubyonrailsrails
rubyonrailsrails
rubyonrailsactionpack_page-caching
-
debiandebian_linux
10.0
Referencias
- https://hackerone.com/reports/1106652ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0009/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4929Third Party Advisory
- https://hackerone.com/reports/1106652ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0009/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4929Third Party Advisory