Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "4:23.3.0-0ubuntu2", "binary_name": "openstack-dashboard" }, { "binary_version": "4:23.3.0-0ubuntu2", "binary_name": "openstack-dashboard-common" }, { "binary_version": "4:23.3.0-0ubuntu2", "binary_name": "openstack-dashboard-ubuntu-theme" }, { "binary_version": "4:23.3.0-0ubuntu2", "binary_name": "python3-django-horizon" }, { "binary_version": "4:23.3.0-0ubuntu2", "binary_name": "python3-django-openstack-auth" } ], "priority_reason": "Per upstream bug, this is a minor issue" }