GHSA-f8fh-xp28-q59m

Suggest an improvement
Source
https://github.com/advisories/GHSA-f8fh-xp28-q59m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f8fh-xp28-q59m/GHSA-f8fh-xp28-q59m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f8fh-xp28-q59m
Aliases
Published
2022-05-24T17:35:25Z
Modified
2024-09-20T22:01:39.240867Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
OpenStack Horizon Open redirect in workflow forms
Details

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.

Database specific
{
    "nvd_published_at": "2020-12-04T08:15:00Z",
    "cwe_ids": [
        "CWE-601"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-29T11:01:41Z"
}
References

Affected packages

PyPI / horizon

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.3.2

Affected versions

12.*

12.0.2
12.0.3
12.0.4

13.*

13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.0
13.0.1
13.0.2
13.0.3

14.*

14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
14.0.0.0rc2
14.0.0
14.0.1
14.0.2
14.0.3
14.0.4
14.1.0

15.*

15.0.0.0b1
15.0.0.0b2
15.0.0.0rc1
15.0.0.0rc2
15.0.0
15.1.0
15.1.1
15.2.0
15.3.0
15.3.1

PyPI / horizon

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16.0.0
Fixed
16.2.1

Affected versions

16.*

16.0.0
16.1.0
16.2.0

PyPI / horizon

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
17.0.0
Fixed
18.3.3

Affected versions

17.*

17.0.0
17.1.0

18.*

18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2

PyPI / horizon

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
18.4.0
Fixed
18.6.0

Affected versions

18.*

18.4.0
18.4.1
18.5.0