{"id":"GHSA-f8fh-xp28-q59m","summary":"OpenStack Horizon Open redirect in workflow forms","details":"An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the \"next\" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.","aliases":["CVE-2020-29565","PYSEC-2020-45"],"modified":"2024-09-20T22:02:11.524463Z","published":"2022-05-24T17:35:25Z","database_specific":{"nvd_published_at":"2020-12-04T08:15:00Z","cwe_ids":["CWE-601"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-29T11:01:41Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-29565"},{"type":"WEB","url":"https://github.com/openstack/horizon/commit/252467100f75587e18df9c43ed5802ee8f0017fa"},{"type":"WEB","url":"https://github.com/openstack/horizon/commit/6c208edf323ced07b15ec4bc3879bddb91d398bc"},{"type":"WEB","url":"https://github.com/openstack/horizon/commit/9e0e333ab5277b6c396f602862ff90398cb0242b"},{"type":"WEB","url":"https://github.com/openstack/horizon/commit/baa370f84332ad41502daea29a551705696f4421"},{"type":"WEB","url":"https://bugs.launchpad.net/horizon/+bug/1865026"},{"type":"PACKAGE","url":"https://github.com/openstack/horizon"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/horizon/PYSEC-2020-45.yaml"},{"type":"WEB","url":"https://review.opendev.org/c/openstack/horizon/+/758841"},{"type":"WEB","url":"https://review.opendev.org/c/openstack/horizon/+/758843"},{"type":"WEB","url":"https://security.openstack.org/ossa/OSSA-2020-008.html"},{"type":"WEB","url":"https://www.debian.org/security/2020/dsa-4820"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2020/12/08/2"}],"affected":[{"package":{"name":"horizon","ecosystem":"PyPI","purl":"pkg:pypi/horizon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.3.2"}]}],"versions":["12.0.2","12.0.3","12.0.4","13.0.0","13.0.0.0b3","13.0.0.0rc1","13.0.0.0rc2","13.0.1","13.0.2","13.0.3","14.0.0","14.0.0.0b1","14.0.0.0b2","14.0.0.0b3","14.0.0.0rc1","14.0.0.0rc2","14.0.1","14.0.2","14.0.3","14.0.4","14.1.0","15.0.0","15.0.0.0b1","15.0.0.0b2","15.0.0.0rc1","15.0.0.0rc2","15.1.0","15.1.1","15.2.0","15.3.0","15.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f8fh-xp28-q59m/GHSA-f8fh-xp28-q59m.json"}},{"package":{"name":"horizon","ecosystem":"PyPI","purl":"pkg:pypi/horizon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16.0.0"},{"fixed":"16.2.1"}]}],"versions":["16.0.0","16.1.0","16.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f8fh-xp28-q59m/GHSA-f8fh-xp28-q59m.json"}},{"package":{"name":"horizon","ecosystem":"PyPI","purl":"pkg:pypi/horizon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"17.0.0"},{"fixed":"18.3.3"}]}],"versions":["17.0.0","17.1.0","18.0.0","18.1.0","18.2.0","18.3.0","18.3.1","18.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f8fh-xp28-q59m/GHSA-f8fh-xp28-q59m.json"}},{"package":{"name":"horizon","ecosystem":"PyPI","purl":"pkg:pypi/horizon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"18.4.0"},{"fixed":"18.6.0"}]}],"versions":["18.4.0","18.4.1","18.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f8fh-xp28-q59m/GHSA-f8fh-xp28-q59m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}