VDB
Sign up
—

PYSEC-2012-18

Quick fix

PYSEC-2012-18 — horizon: upgrade to the fixed version with the command below.

pip install --upgrade 'horizon>=35eada8a27323c0f83c400177797927aba6bc99b'

Details

Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/horizon
Introduced in: 0Fixed in: 35eada8a27323c0f83c400177797927aba6bc99b
Fixpip install --upgrade 'horizon>=35eada8a27323c0f83c400177797927aba6bc99b'

References