{"id":"CVE-2021-22881","aliases":["GHSA-8877-prq4-9xfw"],"url":"https://o3.security/vulnerability/CVE-2021-22881","summary":"Actionpack Open Redirect Vulnerability ","details":"The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain \"allowed host\" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted applications will have allowed hosts with a leading dot. When an allowed host contains a leading dot, a specially crafted `Host` header can be used to redirect to a malicious website.","published":"2021-02-11T18:15:17.460Z","modified":"2026-08-07T11:31:11.470081744Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"actionpack","fixedVersion":"6.0.3.5"},{"ecosystem":"RubyGems","name":"actionpack","fixedVersion":"6.1.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XQ3NS4IBYE2I3MVMGAHFZBZBIZGHXHT3/"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/05/05/2"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2021/08/20/1"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2021/12/14/5"},{"type":"FIX","url":"https://benjamin-bouchet.com/cve-2021-22881-faille-de-securite-dans-le-middleware-hostauthorization/"},{"type":"FIX","url":"https://discuss.rubyonrails.org/t/cve-2021-22881-possible-open-redirect-in-host-authorization-middleware/77130"},{"type":"FIX","url":"https://hackerone.com/reports/1047447"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:11.470081744Z"}}