// For flags

CVE-2020-29565

python-django-horizon: dashboard allows open redirect

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.

Se detectó un problema en OpenStack Horizon versiones 15.3.2, versiones 16.x anteriores a 16.2.1, versiones 17.x y versiones 18.x anteriores a 18.3.3, versiones 18.4.x y 18.5.x. Se presenta una falta de comprobación del parámetro "next", lo que permitiría a alguien proporcionar una URL maliciosa en Horizon que puede causar un redireccionamiento automático a la URL maliciosa proporcionada

A flaw was found in python-django-horizon. The "next" parameter is not correctly validated allowing a remote attacker to supply a malicious URL in the dashboard that could cause an automatic redirect to the provided malicious site. The highest threat from this vulnerability is to data confidentiality and integrity.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-04 CVE Reserved
  • 2020-12-04 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-11-10 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openstack
Search vendor "Openstack"
Horizon
Search vendor "Openstack" for product "Horizon"
>= 15.3.0 < 15.3.2
Search vendor "Openstack" for product "Horizon" and version " >= 15.3.0 < 15.3.2"
-
Affected
Openstack
Search vendor "Openstack"
Horizon
Search vendor "Openstack" for product "Horizon"
>= 16.0.0 < 16.2.1
Search vendor "Openstack" for product "Horizon" and version " >= 16.0.0 < 16.2.1"
-
Affected
Openstack
Search vendor "Openstack"
Horizon
Search vendor "Openstack" for product "Horizon"
>= 17.0.0 < 18.3.3
Search vendor "Openstack" for product "Horizon" and version " >= 17.0.0 < 18.3.3"
-
Affected
Openstack
Search vendor "Openstack"
Horizon
Search vendor "Openstack" for product "Horizon"
>= 18.4.0 <= 18.5.0
Search vendor "Openstack" for product "Horizon" and version " >= 18.4.0 <= 18.5.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
10.0
Search vendor "Debian" for product "Debian Linux" and version "10.0"
-
Affected