Bug 1995940 (CVE-2021-22942) - CVE-2021-22942 rubygem-actionpack: possible open redirect in the Host Authorization middleware
Summary: CVE-2021-22942 rubygem-actionpack: possible open redirect in the Host Authori...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2021-22942
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1995941 1999085
Blocks: 1995943
TreeView+ depends on / blocked
 
Reported: 2021-08-20 09:05 UTC by Marian Rehak
Modified: 2021-08-30 17:57 UTC (History)
34 users (show)

Fixed In Version: rubygem-actionpack 6.1.4.1,rubygem-actionpack 6.0.4.1
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in rubygem-actionpack. Specially crafted “X-Forwarded-Host” headers, in combination with certain “allowed host” formats, can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. The highest threat from this vulnerability is to system availability.
Clone Of:
Environment:
Last Closed: 2021-08-30 17:57:23 UTC


Attachments (Terms of Use)

Description Marian Rehak 2021-08-20 09:05:47 UTC
Specially crafted “X-Forwarded-Host” headers in combination with certain “allowed host” formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.

Reference:

https://weblog.rubyonrails.org/2021/8/19/Rails-6-0-4-1-and-6-1-4-1-have-been-released/

Comment 1 Marian Rehak 2021-08-20 09:06:05 UTC
Created rubygem-actionpack tracking bugs for this issue:

Affects: fedora-all [bug 1995941]

Comment 3 Yadnyawalk Tale 2021-08-30 11:25:45 UTC
Analysis
==========

Earlier, when `config.hosts` has domain name with leading dot (.) some function sanitize this domain name with wrong regex which was leading to redirection. CVE-2021-22881 fixed this by introducing new regex with addition of some auth checks. However, if `config.hosts` has domain name with case sensitivity (for example, .REDHAT.com) redirection was still possible; which is fixed by CVE-2021-22942.

I do see `config.hosts` in development env of upstream foreman but domain name anyway doesn't starts with leading dot (.) - which is required. Additionally, the production env do not have `config.hosts` so this looks safe. Same goes for downstream Satellite. Don't see upstream Katello using any of this.
https://github.com/theforeman/foreman/blob/develop/config/environments/development.rb#L63

Comment 4 Yadnyawalk Tale 2021-08-30 11:35:18 UTC
CVSS explanation:
* AC:H - Assuming victim already have vulnerable configuration settings (i.e. config.hosts with case sensitivity)
* C:L and I:L - Information in the victim's browser associated with the vulnerable rails app can be read (and later modified) by the malicious attacker by directed it any destination the attacker wishes.

Comment 7 Product Security DevOps Team 2021-08-30 17:57:23 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-22942


Note You need to log in before you can comment on or make changes to this bug.