5.8
CVSSv2

CVE-2012-3540

Published: 05/09/2012 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack horizon 2012.1

Vendor Advisories

Synopsis Low: python-django-horizon security update Type/Severity Security Advisory: Low Topic Updated python-django-horizon packages that fix one security issue are nowavailable for Red Hat OpenStack EssexThe Red Hat Security Response Team has rated this update as having lowsecurity impact A Common Vulne ...
Debian Bug report logs - #686050 Tracking CVE-2012-3540 Package: horizon; Maintainer for horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Tue, 28 Aug 2012 03:09:01 UTC Severity: grave Found in version 201211-3 Fixed in version horizon/201211-4 ...
OpenStack Horizon could help expose sensitive information ...