CVE-2022-45582

Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:29

Type Values Removed Values Added
References () https://bugs.launchpad.net/horizon/+bug/1982676 - Issue Tracking, Patch, Vendor Advisory () https://bugs.launchpad.net/horizon/+bug/1982676 - Issue Tracking, Patch, Vendor Advisory
References () https://github.com/openstack/horizon/blob/master/horizon/workflows/views.py#L96-L102 - Issue Tracking () https://github.com/openstack/horizon/blob/master/horizon/workflows/views.py#L96-L102 - Issue Tracking
References () https://lists.debian.org/debian-lts-announce/2023/11/msg00033.html - () https://lists.debian.org/debian-lts-announce/2023/11/msg00033.html -
References () https://lists.debian.org/debian-lts-announce/2023/12/msg00000.html - () https://lists.debian.org/debian-lts-announce/2023/12/msg00000.html -

01 Dec 2023, 06:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2023/12/msg00000.html -

01 Dec 2023, 01:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2023/11/msg00033.html -

30 Aug 2023, 17:12

Type Values Removed Values Added
References (MISC) https://bugs.launchpad.net/horizon/+bug/1982676 - (MISC) https://bugs.launchpad.net/horizon/+bug/1982676 - Issue Tracking, Patch, Vendor Advisory
References (MISC) https://github.com/openstack/horizon/blob/master/horizon/workflows/views.py#L96-L102 - (MISC) https://github.com/openstack/horizon/blob/master/horizon/workflows/views.py#L96-L102 - Issue Tracking
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*
CWE CWE-601
First Time Openstack horizon
Openstack

22 Aug 2023, 20:10

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-22 19:16

Updated : 2024-11-21 07:29


NVD link : CVE-2022-45582

Mitre link : CVE-2022-45582

CVE.ORG link : CVE-2022-45582


JSON object : View

Products Affected

openstack

  • horizon
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')