CVE-2020-29565
published 2020-12-04CVE-2020-29565: An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.40%
69.6th percentile
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | horizon | < horizon 3:18.6.1-1 (bookworm) | horizon 3:18.6.1-1 (bookworm) |
| openstack | horizon | >= 0 < 3:18.6.1-1 | 3:18.6.1-1 |
| openstack | horizon | >= 0 < 3:18.6.1-1 | 3:18.6.1-1 |
| openstack | horizon | >= 0 < 3:18.6.1-1 | 3:18.6.1-1 |
| openstack | horizon | >= 0 < 3:18.6.1-1 | 3:18.6.1-1 |
| openstack | horizon | >= 0 < 15.3.2 | 15.3.2 |
| openstack | horizon | >= 15.3.0 < 15.3.2 | 15.3.2 |
| openstack | horizon | >= 16.0.0 < 16.2.1 | 16.2.1 |
| openstack | horizon | >= 16.0.0 < 16.2.1 | 16.2.1 |
| openstack | horizon | >= 17.0.0 < 18.3.3 | 18.3.3 |
| openstack | horizon | >= 17.0.0 < 18.3.3 | 18.3.3 |
| openstack | horizon | >= 18.4.0 < 18.6.0 | 18.6.0 |
| openstack | horizon | 18.4.0 – 18.5.0 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Horizon vulnerability
vendor_ubuntu·2021-01-05
CVE-2020-29565 OpenStack Horizon vulnerability
Title: OpenStack Horizon vulnerability
Summary: OpenStack Horizon could be made to redirect to a malicious URL.
Pritam Singh discovered that OpenStack Horizon incorrectly validated
certain parameters. An attacker could possibly use this issue to cause
OpenStack Horizon to redirect to a malicious URL.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-django-horizon: dashboard allows open redirect
vendor_redhat·2020-02-26·CVSS 6.1
CVE-2020-29565 [MEDIUM] CWE-601 python-django-horizon: dashboard allows open redirect
python-django-horizon: dashboard allows open redirect
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
A flaw was found in python-django-horizon. The "next" parameter is not correctly validated allowing a remote attacker to supply a malicious URL in the dashboard that could cause an automatic redirect to the provided malicious site. The highest threat from this vulnerability is to data confidentiality and integrity.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet th
Debian
CVE-2020-29565: horizon - An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, ...
vendor_debian·2020·CVSS 6.1
CVE-2020-29565 [MEDIUM] CVE-2020-29565: horizon - An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, ...
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
Scope: local
bookworm: resolved (fixed in 3:18.6.1-1)
bullseye: resolved (fixed in 3:18.6.1-1)
forky: resolved (fixed in 3:18.6.1-1)
sid: resolved (fixed in 3:18.6.1-1)
trixie: resolved (fixed in 3:18.6.1-1)
GHSA
OpenStack Horizon Open redirect in workflow forms
ghsa·2022-05-24
CVE-2020-29565 [MEDIUM] CWE-601 OpenStack Horizon Open redirect in workflow forms
OpenStack Horizon Open redirect in workflow forms
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
OSV
OpenStack Horizon Open redirect in workflow forms
osv·2022-05-24
CVE-2020-29565 [MEDIUM] OpenStack Horizon Open redirect in workflow forms
OpenStack Horizon Open redirect in workflow forms
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
OSV
CVE-2020-29565: An issue was discovered in OpenStack Horizon before 15
osv·2020-12-04·CVSS 6.1
CVE-2020-29565 [MEDIUM] CVE-2020-29565: An issue was discovered in OpenStack Horizon before 15
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2020/12/08/2https://bugs.launchpad.net/horizon/+bug/1865026https://review.opendev.org/c/openstack/horizon/+/758841/https://review.opendev.org/c/openstack/horizon/+/758843/https://security.openstack.org/ossa/OSSA-2020-008.htmlhttps://www.debian.org/security/2020/dsa-4820http://www.openwall.com/lists/oss-security/2020/12/08/2https://bugs.launchpad.net/horizon/+bug/1865026https://review.opendev.org/c/openstack/horizon/+/758841/https://review.opendev.org/c/openstack/horizon/+/758843/https://security.openstack.org/ossa/OSSA-2020-008.htmlhttps://www.debian.org/security/2020/dsa-4820
2020-12-04
Published