Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://bugs.launchpad.net/horizon/+bug/1982676 | patch vendor advisory issue tracking |
https://github.com/openstack/horizon/blob/master/horizon/workflows/views.py#L96-L102 | issue tracking |
https://lists.debian.org/debian-lts-announce/2023/11/msg00033.html | mailing list |
https://lists.debian.org/debian-lts-announce/2023/12/msg00000.html | mailing list |