PYSEC-2020-45

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/horizon/PYSEC-2020-45.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2020-45
Aliases
Published
2020-12-04T08:15:00Z
Modified
2024-04-29T11:26:28.902263Z
Summary
[none]
Details

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.

References

Affected packages

PyPI / horizon

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15.3.0
Fixed
15.3.2
Introduced
16.0.0
Fixed
16.2.1
Introduced
17.0.0
Fixed
18.3.3
Introduced
18.4.0
Fixed
18.6.0

Affected versions

15.*

15.3.0
15.3.1

16.*

16.0.0
16.1.0
16.2.0

17.*

17.0.0
17.1.0

18.*

18.0.0
18.1.0
18.2.0
18.3.0
18.3.1
18.3.2
18.4.0
18.4.1
18.5.0