Specially crafted “X-Forwarded-Host” headers in combination with certain “allowed host” formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
View the template here CVE-2021-44528.yaml
References:
https://seclists.org/oss-sec/2021/q4/att-160/7-0-host-authorzation-open-redirect.patch