CVE-2021-44528
published 2022-01-10CVE-2021-44528: A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain…
PriorityP340medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
4.18%
89.8th percentile
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 6.0.0 < 6.0.4.2 | 6.0.4.2 |
| actionpack_project | actionpack | >= 6.1.0 < 6.1.4.2 | 6.1.4.2 |
| debian | rails | < rails 2:6.1.4.6+dfsg-1 (bookworm) | rails 2:6.1.4.6+dfsg-1 (bookworm) |
| https | github.com_rails_rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | >= 0 < 2:6.0.3.7+dfsg-2+deb11u1 | 2:6.0.3.7+dfsg-2+deb11u1 |
| rubyonrails | rails | >= 0 < 2:6.1.4.6+dfsg-1 | 2:6.1.4.6+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.4.6+dfsg-1 | 2:6.1.4.6+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.4.6+dfsg-1 | 2:6.1.4.6+dfsg-1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: specially crafted "X-Forwarded-Host" headers may lead to open redirect
vendor_redhat·2021-12-14·CVSS 6.1
CVE-2021-44528 [MEDIUM] CWE-601 rubygem-actionpack: specially crafted "X-Forwarded-Host" headers may lead to open redirect
rubygem-actionpack: specially crafted "X-Forwarded-Host" headers may lead to open redirect
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Statement: Red Hat Satellite does not make use of the config.hosts setting and is not affected by this CVE.
Package: tfm-rubygem-actionpack (Red Hat Satellite 6) - Not affected
Debian
CVE-2021-44528: rails - A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an...
vendor_debian·2021·CVSS 6.1
CVE-2021-44528 [MEDIUM] CVE-2021-44528: rails - A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an...
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Scope: local
bookworm: resolved (fixed in 2:6.1.4.6+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1)
forky: resolved (fixed in 2:6.1.4.6+dfsg-1)
sid: resolved (fixed in 2:6.1.4.6+dfsg-1)
trixie: resolved (fixed in 2:6.1.4.6+dfsg-1)
OSV
CVE-2021-44528: A open redirect vulnerability exists in Action Pack >= 6
osv·2022-01-10·CVSS 6.1
CVE-2021-44528 [MEDIUM] CVE-2021-44528: A open redirect vulnerability exists in Action Pack >= 6
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
OSV
actionpack Open Redirect in Host Authorization Middleware
osv·2021-12-14·CVSS 6.1
CVE-2021-44528 [MEDIUM] actionpack Open Redirect in Host Authorization Middleware
actionpack Open Redirect in Host Authorization Middleware
Specially crafted "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Impacted applications will have allowed hosts with a leading dot. For example, configuration files that look like this:
```
config.hosts << '.EXAMPLE.com'
```
When an allowed host contains a leading dot, a specially crafted Host header can be used to redirect to a malicious website.
This vulnerability is similar to CVE-2021-22881 and CVE-2021-22942.
Releases
The fixed releases are available at the normal locations.
Patches
To aid users who aren't able to upgrade immediately we have provided patches for the two supported release seri
GHSA
actionpack Open Redirect in Host Authorization Middleware
ghsa·2021-12-14·CVSS 6.1
CVE-2021-44528 [MEDIUM] CWE-601 actionpack Open Redirect in Host Authorization Middleware
actionpack Open Redirect in Host Authorization Middleware
Specially crafted "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Impacted applications will have allowed hosts with a leading dot. For example, configuration files that look like this:
```
config.hosts << '.EXAMPLE.com'
```
When an allowed host contains a leading dot, a specially crafted Host header can be used to redirect to a malicious website.
This vulnerability is similar to CVE-2021-22881 and CVE-2021-22942.
Releases
The fixed releases are available at the normal locations.
Patches
To aid users who aren't able to upgrade immediately we have provided patches for the two supported release seri
No detection rules found.
Nuclei
Open Redirect in Host Authorization Middleware
nuclei·CVSS 6.1
CVE-2021-44528 [MEDIUM] Open Redirect in Host Authorization Middleware
Open Redirect in Host Authorization Middleware
Specially crafted "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
Template:
id: CVE-2021-44528
info:
name: Open Redirect in Host Authorization Middleware
author: geeknik
severity: medium
description: Specially crafted "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
impact: |
This vulnerability can lead to phishing attacks, where users are tricked into visiting malicious websites and disclosing sensitive information.
remediation: |
Apply the latest security patches or updates provide
No writeups or analysis indexed.
https://github.com/rails/rails/commit/0fccfb9a3097a9c4260c791f1a40b128517e7815https://security.netapp.com/advisory/ntap-20240208-0003/https://www.debian.org/security/2023/dsa-5372https://github.com/rails/rails/commit/0fccfb9a3097a9c4260c791f1a40b128517e7815https://security.netapp.com/advisory/ntap-20240208-0003/https://www.debian.org/security/2023/dsa-5372
2022-01-10
Published