CVE-2020-29565: Medium severity openstack horizon vulnerability
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-29565?
CVE-2020-29565 is a vulnerability in OpenStack Horizon that allows an attacker to supply a malicious URL and cause an automatic redirect.
How severe is CVE-2020-29565?
CVE-2020-29565 has a severity rating of 6.1, which is considered high.
What software versions are affected by CVE-2020-29565?
CVE-2020-29565 affects OpenStack Horizon versions before 15.3.2, 16.x before 16.2.1, 17.x, and 18.x before 18.3.3, 18.4.x, and 18.5.x.
How can I fix CVE-2020-29565?
To fix CVE-2020-29565, it is recommended to upgrade to OpenStack Horizon versions 15.3.2, 16.2.1, 18.3.3, 18.4.x, or 18.5.x, depending on the specific affected version.
Where can I find more information about CVE-2020-29565?
You can find more information about CVE-2020-29565 at the following references: [Reference 1](https://security-tracker.debian.org/tracker/CVE-2020-29565), [Reference 2](https://review.opendev.org/758843), [Reference 3](https://review.opendev.org/758841).