GHSA-8877-prq4-9xfw
GitHub Security Advisory
Actionpack Open Redirect Vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Affected Packages
RubyGems
actionpack
Affected versions:
6.0.0
(fixed in 6.0.3.5)
RubyGems
actionpack
Affected versions:
6.1.0
(fixed in 6.1.2.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 2, 2025 6:46 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.