OpenStack Dashboard (Horizon) CVE-2012-3540 Redirect Module Open Redirection Vulnerability
BID:55329
Info
OpenStack Dashboard (Horizon) CVE-2012-3540 Redirect Module Open Redirection Vulnerability
| Bugtraq ID: | 55329 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-3540 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2012 12:00AM |
| Updated: | May 07 2015 05:15PM |
| Credit: | Thomas Biege |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Redhat OpenStack Essex 0 OpenStack Dashboard (Horizon) 0 |
| Not Vulnerable: | |
Discussion
OpenStack Dashboard (Horizon) CVE-2012-3540 Redirect Module Open Redirection Vulnerability
The OpenStack Dashboard (Horizon) provides a baseline user interface for managing OpenStack services.
OpenStack Dashboard Horizon is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
The OpenStack Dashboard (Horizon) provides a baseline user interface for managing OpenStack services.
OpenStack Dashboard Horizon is prone to an open-redirection vulnerability.
An attacker can leverage this issue by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
Exploit / POC
OpenStack Dashboard (Horizon) CVE-2012-3540 Redirect Module Open Redirection Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.