VDB

CVE-2021-22942

CVE-2021-22942 PUBLISHED CVSS 6.099999904632568 MEDIUM

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

EPSS 1.70% · 75.7th percentile

Risk Scores

CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.70%
75.7th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10rails*, *, 0
Ubuntu:Pro:22.04:LTSrails*, 2:6.1.4.1+dfsg-8ubuntu2+esm1, 0
Ubuntu:24.04:LTSrails2:6.1.7.3+dfsg-2build1, *, 0
Ubuntu:Pro:16.04:LTSrails*, 0, 2:4.1.10-1
Ubuntu:Pro:20.04:LTSrails2:5.2.3+dfsg-3, *, 0
Ubuntu:Pro:18.04:LTSrails2:4.2.10-0ubuntu4, 2:4.2.10-0ubuntu4+esm1, 2:4.2.10-0ubuntu4+esm2

Timeline

  • CVE Published
  • Oct 18, 2021 PoC Published
  • Oct 19, 2021 EPSS Score
  • Nov 18, 2021 PoC Published
  • Dec 15, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 7, 2022 EPSS Score
  • Jun 2, 2022 EPSS Score
  • Jul 30, 2022 EPSS Score
  • Sep 24, 2022 EPSS Score
  • Jan 15, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›