5.8
CVSSv2

CVE-2020-29565

Published: 04/12/2020 Updated: 09/03/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

An issue exists in OpenStack Horizon prior to 15.3.2, 16.x prior to 16.2.1, 17.x and 18.x prior to 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack horizon

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #976872 CVE-2020-29565: Open redirect in workflow forms (OSSA-2020-008) Package: src:horizon; Maintainer for src:horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Tue, 8 Dec 2020 20:15:01 UTC Severity: important Tags: patch, ...
Synopsis Moderate: python-django-horizon security update Type/Severity Security Advisory: Moderate Topic An update for python-django-horizon is now available for Red Hat OpenStackPlatform 13 (Queens)Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerabilit ...
Synopsis Moderate: python-django-horizon security update Type/Severity Security Advisory: Moderate Topic An update for python-django-horizon is now available for Red Hat OpenStackPlatform 161 (Train)Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerabili ...
Pritam Singh discovered an open redirect in the workflow forms of OpenStack Horizon For the stable distribution (buster), this problem has been fixed in version 3:1402-3+deb10u2 We recommend that you upgrade your horizon packages For the detailed security status of horizon please refer to its security tracker page at: security-tracker ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [OSSA-2020-008] horizon: Open redirect in workflow forms (CVE-2020-29565) <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...