Related Vulnerabilities: CVE-2021-22942  

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 before versions 6.1.4.1 and 6.0.4.1 that could allow attackers to redirect users to a malicious website.

Severity Medium

Remote Yes

Type Open redirect

Description

A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 before versions 6.1.4.1 and 6.0.4.1 that could allow attackers to redirect users to a malicious website.

AVG-2493 gitlab-gitaly 14.3.0-2 Medium Vulnerable

AVG-2492 gitlab 14.3.3-1 Medium Vulnerable

https://discuss.rubyonrails.org/t/cve-2021-22942-possible-open-redirect-in-host-authorization-middleware/78722
https://discuss.rubyonrails.org/uploads/short-url/fOROmwJxsyLVKpZo0UO53Dd25u4.patch
https://discuss.rubyonrails.org/uploads/short-url/4SnZzuOjuxtcRaJRLXKX37cVmy4.patch