USN-4675-1

Source
https://ubuntu.com/security/notices/USN-4675-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4675-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-4675-1
Related
Published
2021-01-05T13:20:31.075648Z
Modified
2021-01-05T13:20:31.075648Z
Summary
horizon vulnerability
Details

Pritam Singh discovered that OpenStack Horizon incorrectly validated certain parameters. An attacker could possibly use this issue to cause OpenStack Horizon to redirect to a malicious URL.

References

Affected packages

Ubuntu:16.04:LTS / horizon

Package

Name
horizon
Purl
pkg:deb/ubuntu/horizon@2:9.1.2-0ubuntu5.2?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:9.1.2-0ubuntu5.2

Affected versions

2:8.*

2:8.0.0-0ubuntu2

2:9.*

2:9.0.0~b1-0ubuntu1
2:9.0.0~b1-0ubuntu2
2:9.0.0~b2-0ubuntu1
2:9.0.0~b3-0ubuntu1
2:9.0.0~rc1-0ubuntu1
2:9.0.0-0ubuntu1
2:9.0.0-0ubuntu2
2:9.0.0-0ubuntu2.16.04.1
2:9.0.1-0ubuntu2
2:9.1.0-0ubuntu1
2:9.1.1-0ubuntu1
2:9.1.2-0ubuntu1
2:9.1.2-0ubuntu2
2:9.1.2-0ubuntu3
2:9.1.2-0ubuntu5

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2:9.1.2-0ubuntu5.2",
            "binary_name": "openstack-dashboard"
        },
        {
            "binary_version": "2:9.1.2-0ubuntu5.2",
            "binary_name": "openstack-dashboard-ubuntu-theme"
        },
        {
            "binary_version": "2:9.1.2-0ubuntu5.2",
            "binary_name": "python-django-horizon"
        }
    ]
}

Ubuntu:18.04:LTS / horizon

Package

Name
horizon
Purl
pkg:deb/ubuntu/horizon@3:13.0.3-0ubuntu2?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3:13.0.3-0ubuntu2

Affected versions

3:12.*

3:12.0.0-0ubuntu2.1
3:12.0.0-0ubuntu3

3:13.*

3:13.0.0~b1-0ubuntu1
3:13.0.0~b1-0ubuntu2
3:13.0.0-0ubuntu1
3:13.0.0-0ubuntu1.1
3:13.0.1-0ubuntu1
3:13.0.1-0ubuntu2
3:13.0.1-0ubuntu3
3:13.0.1-0ubuntu4
3:13.0.1-0ubuntu5
3:13.0.1-0ubuntu6
3:13.0.2-0ubuntu1
3:13.0.2-0ubuntu2
3:13.0.2-0ubuntu3
3:13.0.3-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3:13.0.3-0ubuntu2",
            "binary_name": "openstack-dashboard"
        },
        {
            "binary_version": "3:13.0.3-0ubuntu2",
            "binary_name": "openstack-dashboard-ubuntu-theme"
        },
        {
            "binary_version": "3:13.0.3-0ubuntu2",
            "binary_name": "python-django-horizon"
        },
        {
            "binary_version": "3:13.0.3-0ubuntu2",
            "binary_name": "python-django-openstack-auth"
        },
        {
            "binary_version": "3:13.0.3-0ubuntu2",
            "binary_name": "python3-django-openstack-auth"
        }
    ]
}

Ubuntu:20.04:LTS / horizon

Package

Name
horizon
Purl
pkg:deb/ubuntu/horizon@3:18.3.2-0ubuntu0.20.04.4?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3:18.3.2-0ubuntu0.20.04.4

Affected versions

3:16.*

3:16.0.0-0ubuntu1

3:17.*

3:17.0.0~b1~git2019121712.f7313b74c-0ubuntu1

3:18.*

3:18.0.1~git2020021409.bb959361b-0ubuntu2
3:18.0.1~git2020021409.bb959361b-0ubuntu3
3:18.2.1~git2020032709.2c4470272-0ubuntu1
3:18.2.1~git2020041013.754804667-0ubuntu1
3:18.2.1~git2020041013.754804667-0ubuntu2
3:18.2.1~git2020041013.754804667-0ubuntu3
3:18.3.2-0ubuntu0.20.04.1
3:18.3.2-0ubuntu0.20.04.2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3:18.3.2-0ubuntu0.20.04.4",
            "binary_name": "openstack-dashboard"
        },
        {
            "binary_version": "3:18.3.2-0ubuntu0.20.04.4",
            "binary_name": "openstack-dashboard-common"
        },
        {
            "binary_version": "3:18.3.2-0ubuntu0.20.04.4",
            "binary_name": "openstack-dashboard-ubuntu-theme"
        },
        {
            "binary_version": "3:18.3.2-0ubuntu0.20.04.4",
            "binary_name": "python3-django-horizon"
        },
        {
            "binary_version": "3:18.3.2-0ubuntu0.20.04.4",
            "binary_name": "python3-django-openstack-auth"
        }
    ]
}