BIT-rails-2021-44528

Import Source
https://github.com/bitnami/vulndb/tree/main/data/rails/BIT-rails-2021-44528.json
Aliases
Published
2024-03-06T11:03:24.891Z
Modified
2024-03-06T17:05:41.420Z
Details

A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.

References

Affected packages

Bitnami / rails

Package

Name
rails

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0-rc2
Last affected
7.0.0-rc2