CVE-2012-3540
published 2012-09-05CVE-2012-3540: Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web…
PriorityP422medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.90%
85.4th percentile
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 2012.1.1-4 (bookworm) | horizon 2012.1.1-4 (bookworm) |
| debian | keystone | < keystone 2012.1.1-5 (bookworm) | keystone 2012.1.1-5 (bookworm) |
| openstack | essex | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| openstack | horizon | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| openstack | horizon | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| openstack | horizon | >= 0 < 2012.1.1-4 | 2012.1.1-4 |
| openstack | keystone | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | keystone | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | keystone | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | keystone | >= 0 < 2012.1.1-5 | 2012.1.1-5 |
| openstack | keystone | >= 0 < 2012.1 | 2012.1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa5.8MEDIUM
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Horizon vulnerability
vendor_ubuntu·2012-09-13
CVE-2012-3540 OpenStack Horizon vulnerability
Title: OpenStack Horizon vulnerability
Summary: OpenStack Horizon could help expose sensitive information.
Thomas Biege discovered that the Horizon authentication mechanism
did not validate the next parameter. An attacker could use this to
construct a link to legitimate OpenStack web dashboard that redirected
the user to a malicious website after authentication.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Keystone: Lack of authorization for adding users to tenants
vendor_redhat·2012-08-30·CVSS 5.8
CVE-2012-3542 [MEDIUM] Keystone: Lack of authorization for adding users to tenants
Keystone: Lack of authorization for adding users to tenants
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
Red Hat
OpenStack-Horizon: Open redirect through 'next' parameter
vendor_redhat·2012-08-30·CVSS 5.8
CVE-2012-3540 [MEDIUM] OpenStack-Horizon: Open redirect through 'next' parameter
OpenStack-Horizon: Open redirect through 'next' parameter
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
Debian
CVE-2012-3540: horizon - Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horiz...
vendor_debian·2012·CVSS 5.8
CVE-2012-3540 [MEDIUM] CVE-2012-3540: horizon - Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horiz...
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
Scope: local
bookworm: resolved (fixed in 2012.1.1-4)
bullseye: resolved (fixed in 2012.1.1-4)
forky: resolved (fixed in 2012.1.1-4)
sid: resolved (fixed in 2012.1.1-4)
trixie: resolved (fixed in 2012.1.1-4)
Debian
CVE-2012-3542: keystone - OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack ...
vendor_debian·2012·CVSS 5.8
CVE-2012-3542 [MEDIUM] CVE-2012-3542: keystone - OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack ...
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
Scope: local
bookworm: resolved (fixed in 2012.1.1-5)
bullseye: resolved (fixed in 2012.1.1-5)
forky: resolved (fixed in 2012.1.1-5)
sid: resolved (fixed in 2012.1.1-5)
trixie: resolved (fixed in 2012.1.1-5)
GHSA
OpenStack Keystone Allows Remote User Account Creation
ghsa·2022-05-17·CVSS 5.8
CVE-2012-3542 [MEDIUM] CWE-284 OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
OSV
OpenStack Keystone Allows Remote User Account Creation
osv·2022-05-17·CVSS 5.8
CVE-2012-3542 [MEDIUM] OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone Allows Remote User Account Creation
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
GHSA
GHSA-j72v-mpwp-rg79: Open redirect vulnerability in views/auth_forms
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2012-3540 [MEDIUM] CWE-20 GHSA-j72v-mpwp-rg79: Open redirect vulnerability in views/auth_forms
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
OSV
CVE-2012-3542: OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012
osv·2012-09-05·CVSS 5.8
CVE-2012-3542 [MEDIUM] CVE-2012-3542: OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.
OSV
CVE-2012-3540: Open redirect vulnerability in views/auth_forms
osv·2012-09-05·CVSS 5.8
CVE-2012-3540 [MEDIUM] CVE-2012-3540: Open redirect vulnerability in views/auth_forms
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter [epel-6]
bugzilla·2012-08-30·CVSS 5.8
CVE-2012-3540 [MEDIUM] CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter [epel-6]
CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
Bugzilla
CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter [fedora-17]
bugzilla·2012-08-30·CVSS 5.8
CVE-2012-3540 [MEDIUM] CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter [fedora-17]
CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=
Bugzilla
CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter
bugzilla·2012-08-28·CVSS 5.8
CVE-2012-3540 [MEDIUM] CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter
CVE-2012-3540 OpenStack-Horizon: Open redirect through 'next' parameter
Russel Bryant ([email protected]) from the OpenStack Project reports:
Title: Open redirect through 'next' parameter
Impact: Medium
Reporter: Thomas Biege (SUSE)
Products: Horizon
Affects: Essex
Description:
Thomas Biege from SUSE reported a vulnerability in Horizon
authentication mechanism. By adding a malicious 'next' parameter to a
Horizon authentication URL and enticing an unsuspecting user to follow
it, the victim might get redirected after authentication to a
malicious site where useful information could be extracted. Only
setups running Essex are affected.
Proposed patch:
See attached diff. This proposed patch will be merged into the
stable/essex branch on the public disclosure date.
Discussion:
Created at
http://secunia.com/advisories/50480http://www.openwall.com/lists/oss-security/2012/08/30/4http://www.openwall.com/lists/oss-security/2012/08/30/5http://www.securityfocus.com/bid/55329http://www.ubuntu.com/usn/USN-1565-1https://bugs.launchpad.net/horizon/+bug/1039077https://exchange.xforce.ibmcloud.com/vulnerabilities/78196https://github.com/openstack/horizon/commit/35eada8a27323c0f83c400177797927aba6bc99bhttps://lists.launchpad.net/openstack/msg16278.htmlhttps://lists.launchpad.net/openstack/msg16281.htmlhttp://secunia.com/advisories/50480http://www.openwall.com/lists/oss-security/2012/08/30/4http://www.openwall.com/lists/oss-security/2012/08/30/5http://www.securityfocus.com/bid/55329http://www.ubuntu.com/usn/USN-1565-1https://bugs.launchpad.net/horizon/+bug/1039077https://exchange.xforce.ibmcloud.com/vulnerabilities/78196https://github.com/openstack/horizon/commit/35eada8a27323c0f83c400177797927aba6bc99bhttps://lists.launchpad.net/openstack/msg16278.htmlhttps://lists.launchpad.net/openstack/msg16281.html
2012-09-05
Published