|
Message-ID: <CAE4Awf8zd+J4vhSv=cypMur2F24PxFnfsLZJsjZUzaHviQRTjA@mail.gmail.com> Date: Mon, 7 Dec 2020 16:43:33 -0600 From: Gage Hugo <gagehugo@...il.com> To: oss-security@...ts.openwall.com Subject: [OSSA-2020-008] horizon: Open redirect in workflow forms (CVE-2020-29565) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================== OSSA-2020-008: Open redirect in workflow forms ============================================== :Date: December 03, 2020 :CVE: CVE-2020-29565 Affects ~~~~~~~ - - Horizon: <15.3.2, >=16.0.0 <16.2.1, >=17.0.0 <18.3.3, >=18.4.0 <18.6.0 Description ~~~~~~~~~~~ Pritam Singh (Red Hat) reported a vulnerability in Horizon's workflow forms. Previously there was a lack of validation on the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL. Patches ~~~~~~~ - - https://review.opendev.org/758843 (Stein) - - https://review.opendev.org/758841 (Train) Credits ~~~~~~~ - - Pritam Singh from Red Hat (CVE-2020-29565) References ~~~~~~~~~~ - - https://launchpad.net/bugs/1865026 - - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29565 -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWa125cLHIuv6ekof56j9K3b+vREFAl/OrjwACgkQ56j9K3b+ vRG/Gg//Tyj5La8eFwIrwhpDbV/tKNFS+t3NzuhJzLS24WNS9cLf5yDronRdBPdT Ow2OegTZ7K5GyoRARpycTjtE66RIizX9I8Kx27FXPc83hLYYOs/MButYpqcp0swM 687RXZGFcZ5HZtPuRuTcclEcyhzvcUX7HXmznOCmVOHchr+RXzmp6cXC7tyCuNkV cGuuMtptDfkFmn2MpGmiTWEiMusMRbV5HqeyY39jg5dwph0kbMCcuzkX6c2WHubE T+rjVKbmqHr+v7og6mkZoK+pVk6Ulta/lGsYh/0NlszdQw3poN4FIt//TIwJZVwx WSlbMt6IwBW5XiPXvjpX9Awis6CT0jxlIV5XBq+klr3Jo+YnDsChElIPQs3CRKoM vqXVextHCk3LK1Evs3FkBns2Taro4tWOlkGYKR6INT4F1TJKNIzIUiF08673uF3B 8zXDfnVEb7tEMqwu6OdVnfQQ4SRu7uyrN1sHhtwIyfK10AAI7gfJL/wbItJy21Om SQahTfDnikEY5gYYU+NH0LBMXkE0I/T+uvPh4LgP7wUxCMR9uI8+iA0711Gp/aPD WUdm3pUfIJYE7Gq6sT7BJQftHyMPcxOBj+MIrmFDFOxyPV70Mub+f34zxdu3Qoda tZNpy/BGL19VqrlRa9R8H65tzzNy7k5GqkaUYEF5/LegfUgZOTo= =jr+k -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.