Safety vulnerability ID: 39226
The information on this page was manually curated by our Cybersecurity Intelligence Team.
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL. See CVE-2020-29565.
Latest version: 25.1.0
OpenStack Dashboard
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL. See CVE-2020-29565.
MISC:https://bugs.launchpad.net/horizon/+bug/1865026: https://bugs.launchpad.net/horizon/+bug/1865026
MISC:https://review.opendev.org/c/openstack/horizon/+/758841/: https://review.opendev.org/c/openstack/horizon/+/758841/
MISC:https://review.opendev.org/c/openstack/horizon/+/758843/: https://review.opendev.org/c/openstack/horizon/+/758843/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application