CVE-2021-44528
Description
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
CWE
- CWE-601 — Open Redirect (CWE-601)
Affected
- n/a / https://github.com/rails/rails — v=6.1.4.2, 6.0.4.2, 7.0.0.rc2 [affected]
CVSS
- (none)
References
- https://github.com/rails/rails/commit/0fccfb9a3097a9c4260c791f1a40b128517e7815
- https://www.debian.org/security/2023/dsa-5372 vendor-advisory
- https://security.netapp.com/advisory/ntap-20240208-0003/
Source
cvelistV5-main/cves/2021/44xxx/CVE-2021-44528.json