S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-44528 Scanner

CVE-2021-44528 scanner - Open Redirect vulnerability in rails/rails

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-44528
6.1
CVSS

A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
https://github.com/rails/railsby n/a
6.1.4.2, 6.0.4.2, 7.0.0.rc2
Updated Aug 21, 2026View on NVD →
Detail

Rails, also known as Ruby on Rails, is a popular and widely used web application framework written in the Ruby programming language. It is used to build dynamic and interactive web applications with ease. In Rails, developers can quickly create models, views, and controllers that work together seamlessly. With its powerful backend features, Rails has been widely adopted by companies of all sizes, including Airbnb, GitHub, and Shopify.

The CVE-2021-44528 vulnerability, detected in Rails version 6.0.0 and above, is an open redirect vulnerability that can be exploited when a crafted "X-Forwarded-Host" header is combined with certain "allowed host" formats. The vulnerability exists in the Host Authorization middleware, which is used to redirect users to a specific website. With this vulnerability, an attacker can create a link that appears to be a trusted site, but in reality, the link will redirect the user to a malicious site controlled by the attacker.

When exploited, the CVE-2021-44528 vulnerability can lead to severe consequences, including stealing sensitive information from users, distributing malware, and conducting phishing attacks. An attacker can use the open redirect to lure users into clicking on a link that disguises a malicious site as a trusted source, revealing sensitive information such as login credentials and financial information.

At S4E, our advanced platform provides a comprehensive solution to detect and prevent vulnerabilities in digital assets. With our pro features, including vulnerability scanning, patch management, and continuous monitoring, individuals and businesses can rest assured that their digital assets are secure. Take a proactive approach to security and sign up for S4E today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions should be taken:

  • Update Rails to the latest version
  • Implement strict validation of "allowed host" formats
  • Disable automatic redirection in Host Authorization middleware
  • Regularly perform penetration testing and vulnerability scanning
  • Educate users on how to identify and avoid phishing attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.