PT-2012-4795 · Openstack · Openstack Dashboard

Thomas Biege

·

Published

2012-09-05

·

Updated

2023-02-13

·

CVE-2012-3540

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Dashboard (Horizon) version 2012.1
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to the "/auth/login/" API endpoint.
Recommendations For OpenStack Dashboard (Horizon) version 2012.1, as a temporary workaround, consider restricting access to the /auth/login/ API endpoint to minimize the risk of exploitation. Avoid using the next parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2012-3540
PYSEC-2012-18
RHSA-2012:1380

Affected Products

Openstack Dashboard