CVE-2021-22942: Medium severity rubyonrails Rails vulnerability
Overview
There is a possible open redirect vulnerability in the Host Authorization middleware in Action Pack. This vulnerability has been assigned the CVE identifier CVE-2021-22942.
Versions Affected: >= 6.0.0. Not affected: < 6.0.0 Fixed Versions: 6.1.4.1, 6.0.4.1
Impact
Specially crafted “X-Forwarded-Host” headers in combination with certain “allowed host” formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Impacted applications will have allowed hosts with a leading dot. For example, configuration files that look like this:
ruby config.hosts << '.EXAMPLE.com'
When an allowed host contains a leading dot, a specially crafted Host header can be used to redirect to a malicious website.
This vulnerability is similar to CVE-2021-22881, but CVE-2021-22881 did not take in to account domain name case sensitivity.
Releases
The fixed releases are available at the normal locations.
Workarounds
In the case a patch can’t be applied, the following monkey patch can be used in an initializer:
ruby module ActionDispatch class HostAuthorization HOSTNAME = /[a-z0-9.-]+|\[[a-f0-9]:[a-f0-9.:]+\]/i VALIDORIGINHOST = /\A(#{HOSTNAME})(?::\d+)?\z/ VALIDFORWARDEDHOST = /(?:\A|,[ ]?)(#{HOSTNAME})(?::\d+)?\z/
private def authorized?(request) originhost = request.getheader("HTTPHOST")&.slice(VALIDORIGINHOST, 1) || "" forwardedhost = request.xforwardedhost&.slice(VALIDFORWARDEDHOST, 1) || "" @permissions.allows?(originhost) && (forwardedhost.blank? || @permissions.allows?(forwardedhost)) end end end
Other sources
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-22942?
CVE-2021-22942 is a possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0.
How does CVE-2021-22942 affect users?
CVE-2021-22942 could allow attackers to redirect users to a malicious website.
What is the severity of CVE-2021-22942?
CVE-2021-22942 has a severity rating of 6.1 (high).
How can I fix CVE-2021-22942?
There is no available fix for CVE-2021-22942 at the moment. It is recommended to monitor the official security sources for any updates or patches.
Where can I find more information about CVE-2021-22942?
You can find more information about CVE-2021-22942 at the following references: [link1](https://security-tracker.debian.org/tracker/CVE-2021-22942), [link2](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22942), [link3](https://www.openwall.com/lists/oss-security/2021/08/20/1)