hiptest / hiptest-publisher

Publisher for CucumberStudio projects

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2021-22942 (Medium) detected in actionpack-5.2.6.gem - autoclosed

mend-for-github-com opened this issue · comments

CVE-2021-22942 - Medium Severity Vulnerability

Vulnerable Library - actionpack-5.2.6.gem

Web apps on Rails. Simple, battle-tested conventions for building and testing MVC web applications. Works with any Rack-compatible server.

Library home page: https://rubygems.org/gems/actionpack-5.2.6.gem

Dependency Hierarchy:

  • i18n-tasks-0.9.33.gem (Root Library)
    • rails-i18n-5.1.3.gem
      • railties-5.2.6.gem
        • actionpack-5.2.6.gem (Vulnerable Library)

Found in HEAD commit: cd942bec4a4298c7571256500471df1ff912363c

Found in base branch: master

Vulnerability Details

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

Publish Date: 2021-10-18

URL: CVE-2021-22942

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/rubysec/ruby-advisory-db/blob/3f8ecbabcb7daa96eb3f29c211f5dcf5004e2639/gems/actionpack/CVE-2021-22942.yml

Release Date: 2021-01-07

Fix Resolution: actionpack - 6.0.4.1, 6.1.4.1

✔️ This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.