USN-4675-1: OpenStack Horizon vulnerability

05 January 2021

OpenStack Horizon could be made to redirect to a malicious URL.

Releases

Packages

  • horizon - Web interface for OpenStack cloud infrastructure

Details

Pritam Singh discovered that OpenStack Horizon incorrectly validated
certain parameters. An attacker could possibly use this issue to cause
OpenStack Horizon to redirect to a malicious URL.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 20.04
Ubuntu 18.04
Ubuntu 16.04

In general, a standard system update will make all the necessary changes.

References