-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.0668
                       Ruby on Rails Vulnerabilities
                             23 February 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Ruby on Rails
Publisher:         FreeBSD
Operating System:  FreeBSD
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Denial of Service              -- Remote/Unauthenticated      
                   Provide Misleading Information -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-22881 CVE-2021-22880 

Original Bulletin: 
   http://www.vuxml.org/freebsd/8e670b85-706e-11eb-abb2-08002728f74c.html

- --------------------------BEGIN INCLUDED TEXT--------------------

Rails -- multiple vulnerabilities


Affected packages
		rubygem-activerecord52 	< 	5.2.4.5
		rubygem-actionpack60 	< 	6.0.3.5
		rubygem-activerecord60 	< 	6.0.3.5
		rubygem-actionpack61 	< 	6.1.2.1
		rubygem-activerecord61 	< 	6.1.2.1

Details
VuXML ID 	8e670b85-706e-11eb-abb2-08002728f74c
Discovery 	2021-02-10
Entry 		2021-02-17

Ruby on Rails blog:

    Rails version 5.2.4.5, 6.0.3.5 and 6.1.2.1 have been released! Those version are security releases and addresses two issues:

    CVE-2021-22880: Possible DoS Vulnerability in Active Record PostgreSQL adapter.

    CVE-2021-22881: Possible Open Redirect in Host Authorization Middleware.

References
CVE Name : CVE-2021-22880
CVE Name : CVE-2021-22881
URL 	 : https://discuss.rubyonrails.org/t/cve-2021-22880-possible-dos-vulnerability-in-active-record-postgresql-adapter/77129
URL 	 : https://discuss.rubyonrails.org/t/cve-2021-22881-possible-open-redirect-in-host-authorization-middleware/77130
URL 	 : https://weblog.rubyonrails.org/2021/2/10/Rails-5-2-4-5-6-0-3-5-and-6-1-2-1-have-been-released/


Copyright © 2003-2005 Jacques Vidrine and contributors.
Please see the source of this document for full copyright information.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYDR+z+NLKJtyKPYoAQgKZhAAkJM2L9azuXjArxotv3coUXEyx+k1vRtA
rlJ6j1MwKU5WMw9EtVYQ7620CH3m/5n8FrON5eFCn7TzgWDmH7pnNY4ceK/CFDz+
OaJs36fwP8At2zs8wTlbbNYPGEMA0hmV9sRoCa0yPC7zq+KJ2ii2RLm4yOwDlGpr
nwIHdaJBlQsvMz77hqpBG3PnxMVmaVxwoqG3delN+DjWpJgAU82fXein8KEPlwR6
IElQ1C40vbo7ZOcyKtkKJVd195UBb+QlYOMhWHPImAxF2Ywbu9be1x2kjMORxAVr
JFzQ3EU6HJA9cBZbmXxqez/aOEVLA6YiVB5NkHDHtK5hXupbJWo+lgzFTve50ihE
31hC6RHhiBtT2mnpJnHe6a87THCXr1Oi9i6mxnJiw2m9vUKxYCAxQBXhQmFjvh+h
sgfuZzsyKh31LkFh4sxkcqLvvN2Rc9AzIaUONenllW95LqVBaAFacV1eroXMM+8j
4EN3WHh/a8pJC297ss5GfzXOXjn0QEu2foro3hIosg2IIo/vpH7bvvNe+e8S628N
VMbeynZ2H2SQTNa2bbuJkf9CdjQMQ//cnlomBVsBa6hRcMB/C/IGnDsg5BvcEz5H
3uBhoO+bEv2sRNm+/pxOoMm4NNHytWu52EbpTRH02+9XSPnuazZQlnGv4yLWczhK
CDA6idxsXZU=
=mKpT
-----END PGP SIGNATURE-----