A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2022-01-07T00:00:00

Updated: 2024-08-04T04:25:16.854Z

Reserved: 2021-12-02T00:00:00

Link: CVE-2021-44528

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-10T14:10:26.117

Modified: 2024-02-08T10:15:08.973

Link: CVE-2021-44528

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-12-14T00:00:00Z

Links: CVE-2021-44528 - Bugzilla