A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2022-01-07T00:00:00

Updated: 2024-02-08T10:06:07.329850

Reserved: 2021-12-02T00:00:00


Link: CVE-2021-44528

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-01-10T14:10:26.117

Modified: 2024-02-08T10:15:08.973


Link: CVE-2021-44528

JSON object: View

cve-icon Redhat Information

No data.

CWE