cbcvebase.
CVE-2012-3540
published 2012-09-05

CVE-2012-3540: Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web…

PriorityP422medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.90%
85.4th percentile
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianhorizon< horizon 2012.1.1-4 (bookworm)horizon 2012.1.1-4 (bookworm)
debiankeystone< keystone 2012.1.1-5 (bookworm)keystone 2012.1.1-5 (bookworm)
openstackessex
openstackhorizon
openstackhorizon
openstackhorizon>= 0 < 2012.1.1-42012.1.1-4
openstackhorizon>= 0 < 2012.1.1-42012.1.1-4
openstackhorizon>= 0 < 2012.1.1-42012.1.1-4
openstackhorizon>= 0 < 2012.1.1-42012.1.1-4
openstackkeystone>= 0 < 2012.1.1-52012.1.1-5
openstackkeystone>= 0 < 2012.1.1-52012.1.1-5
openstackkeystone>= 0 < 2012.1.1-52012.1.1-5
openstackkeystone>= 0 < 2012.1.1-52012.1.1-5
openstackkeystone>= 0 < 2012.12012.1

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa5.8MEDIUM
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.