VDB

CVE-2021-22942

CVE-2021-22942 PUBLISHED

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

EPSS 0.53% · 67.7th percentile

Risk Scores

EPSS Score
0.53%
67.7th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10rails*, *, 0
Ubuntu:Pro:22.04:LTSrails*, 2:6.1.4.1+dfsg-8ubuntu2+esm1, 0
Ubuntu:24.04:LTSrails2:6.1.7.3+dfsg-2build1, *, 0
Ubuntu:Pro:16.04:LTSrails*, 0, 2:4.1.10-1
Ubuntu:Pro:20.04:LTSrails2:5.2.3+dfsg-3, *, 0
Ubuntu:Pro:18.04:LTSrails2:4.2.10-0ubuntu4, 2:4.2.10-0ubuntu4+esm1, 2:4.2.10-0ubuntu4+esm2

Timeline

  • CVE Published
  • Oct 18, 2021 PoC Published
  • Oct 19, 2021 EPSS Score
  • Nov 18, 2021 PoC Published
  • Dec 14, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 6, 2022 EPSS Score
  • Jun 1, 2022 EPSS Score
  • Jul 28, 2022 EPSS Score
  • Sep 22, 2022 EPSS Score
  • Nov 18, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›