Vulnerabilities
Vulnerable Software
Rubyonrails:  >> Rails  >> 6.0.3.3  Security Vulnerabilities
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted applications will have allowed hosts with a leading dot. When an allowed host contains a leading dot, a specially crafted `Host` header can be used to redirect to a malicious website.
CVSS Score
6.1
EPSS Score
0.069
Published
2021-02-11
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-01-06


Contact Us

Shodan ® - All rights reserved