Information disclosure in Ruby on Rails - CVE-2021-22885

 

Information disclosure in Ruby on Rails - CVE-2021-22885

Published: May 10, 2021


Vulnerability identifier: #VU53001
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22885
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to improper input validation in the Action Pack within the "redirect_to" or "polymorphic_url" helper. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

Ruby on Rails
IBM Cloud Pak for Multicloud Management
SUSE Webyast
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise High Availability
openEuler
rails (Debian package)
rubygem-actionpack-3_2
ruby2.1-rubygem-actionpack-4_2
ruby2.5-rubygem-actionpack-5_1
rubygem-actionpack
rubygem-actionpack-doc

How to mitigate CVE-2021-22885

Install updates from vendor's website.

Ruby on Rails - addressed in versions 5.2.4.6, 5.2.6, 6.0.3.7, 6.1.3.2
rails (Debian package) - update to 2:5.2.2.1+dfsg-1+deb10u3
rubygem-actionpack-3_2 - update to 3.2.12-0.27.3.1
ruby2.1-rubygem-actionpack-4_2 - update to 4.2.9-7.12.1
ruby2.5-rubygem-actionpack-5_1 - update to 5.1.4-3.9.1
rubygem-actionpack - update to 5.2.4.4-2
rubygem-actionpack-doc - update to 5.2.4.4-2

External References

Related Security Bulletins