CVE-2021-22885
Summary
| CVE | CVE-2021-22885 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-27 12:15:00 UTC |
| Updated | 2022-04-06 16:58:00 UTC |
| Description | A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178588 Debian Security Update for rails (DLA 2655-1)
- 178665 Debian Security Update for rails (DSA 4929-1)
- 180567 Debian Security Update for rails (CVE-2021-22885)
- 239895 Red Hat Update for Satellite 6.10 (RHSA-2021:4702)
- 690146 Free Berkeley Software Distribution (FreeBSD) Security Update for rails (f7a00ad7-ae75-11eb-8113-08002728f74c)
- 750190 OpenSUSE Security Update for rubygem-actionpack-5_1 (openSUSE-SU-2021:0797-1)
- 750777 OpenSUSE Security Update for rubygem-actionpack-5_1 (openSUSE-SU-2021:1759-1)