VDB
CVE-2012-3540
CVE-2012-3540
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
EPSS 2.92% · 86.0th percentile
Risk Scores
CVSS 2.0
5.800000190734863
EPSS Score
2.92%
86.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| openstack | horizon | 2012.1 |
Timeline
- Sep 5, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- openstackdashboard-next-open-redirect(78196) vdb
- USN-1565-1 vendor-advisory
- [oss-security] 20120830 Re: [Openstack] [OSSA 2012-012] Horizon, Open redirect through 'next' parameter (CVE-2012-3540) mailing-list
- http://www.openwall.com/lists/oss-security/2012/08/30/4 technical
- http://www.securityfocus.com/bid/55329 technical
- http://secunia.com/advisories/50480 advisory
- https://bugs.launchpad.net/horizon/+bug/1039077 technical
- https://github.com/openstack/horizon/commit/35eada8a27323c0f83c400177797927aba6bc99b exploit
- https://lists.launchpad.net/openstack/msg16281.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2012-3540 advisory
- https://lists.launchpad.net/openstack/msg16278.html url