Oval Definition:oval:org.opensuse.security:def:202122903
Revision Date:2022-05-22Version:1
Title:CVE-2021-22903
Description:

The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, `config.hosts << "sub.example.com"` to permit a request with a Host header value of `sub-example.com`.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-22903
SUSE CVE-2021-22903
Platform(s):SUSE OpenStack Cloud 7
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND ruby2.1-rubygem-actionpack-4_2 is not affected
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND rubygem-actionpack-4_2 is not affected
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND ruby2.1-rubygem-actionpack-4_2 is not affected
  • BACK