CVE-2021-22942 log

Source
Severity Medium
Remote Yes
Type Open redirect
Description
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 before versions 6.1.4.1 and 6.0.4.1 that could allow attackers to redirect users to a malicious website.
Group Package Affected Fixed Severity Status Ticket
AVG-2493 gitlab-gitaly 14.3.0-3 Medium Vulnerable
AVG-2492 gitlab 14.3.3-2 14.5.0-1 Medium Fixed
References
https://discuss.rubyonrails.org/t/cve-2021-22942-possible-open-redirect-in-host-authorization-middleware/78722
https://discuss.rubyonrails.org/uploads/short-url/fOROmwJxsyLVKpZo0UO53Dd25u4.patch
https://discuss.rubyonrails.org/uploads/short-url/4SnZzuOjuxtcRaJRLXKX37cVmy4.patch