PT-2020-5798 · Openstack+2 · Openstack Horizon+2
Pritam Singh
·
Published
2020-02-27
·
Updated
2022-05-24
·
CVE-2020-29565
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenStack Horizon versions prior to 15.3.2
OpenStack Horizon versions 16.x prior to 16.2.1
OpenStack Horizon versions 17.x and 18.x prior to 18.3.3
OpenStack Horizon versions 18.4.x and 18.5.x
Description:
The issue is related to a lack of validation of the
next parameter in OpenStack Horizon. This allows an attacker to supply a malicious URL that can cause an automatic redirect to the provided malicious URL, potentially leading to unauthorized access to confidential data and disruption of its integrity.Recommendations:
For OpenStack Horizon versions prior to 15.3.2, update to version 15.3.2 or later.
For OpenStack Horizon versions 16.x prior to 16.2.1, update to version 16.2.1 or later.
For OpenStack Horizon versions 17.x and 18.x prior to 18.3.3, update to version 18.3.3 or later.
For OpenStack Horizon versions 18.4.x and 18.5.x, consider disabling the use of the
next parameter until a patch is available.
As a temporary workaround, consider restricting access to the vulnerable interface to minimize the risk of exploitation.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Openstack Horizon
Ubuntu